Lucene search

K
cveZephyrCVE-2021-3329
HistoryFeb 26, 2023 - 7:15 a.m.

CVE-2021-3329

2023-02-2607:15:10
CWE-665
CWE-703
zephyr
web.nvd.nist.gov
19
cve-2021-3329
validation
hci host
bluetooth stack
nvd

CVSS3

9.6

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:H

AI Score

6.4

Confidence

High

EPSS

0.001

Percentile

20.6%

Lack of proper validation in HCI Host stack initialization can cause a crash of the bluetooth stack

Affected configurations

Nvd
Node
zephyrprojectzephyrMatch2.4.0-
OR
zephyrprojectzephyrMatch2.4.0rc1
OR
zephyrprojectzephyrMatch2.4.0rc2
OR
zephyrprojectzephyrMatch2.4.0rc3
VendorProductVersionCPE
zephyrprojectzephyr2.4.0cpe:2.3:o:zephyrproject:zephyr:2.4.0:-:*:*:*:*:*:*
zephyrprojectzephyr2.4.0cpe:2.3:o:zephyrproject:zephyr:2.4.0:rc1:*:*:*:*:*:*
zephyrprojectzephyr2.4.0cpe:2.3:o:zephyrproject:zephyr:2.4.0:rc2:*:*:*:*:*:*
zephyrprojectzephyr2.4.0cpe:2.3:o:zephyrproject:zephyr:2.4.0:rc3:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "zephyrproject-rtos",
    "product": "zephyr",
    "versions": [
      {
        "version": "unspecified",
        "lessThanOrEqual": "v2.4",
        "status": "affected",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

9.6

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:H

AI Score

6.4

Confidence

High

EPSS

0.001

Percentile

20.6%

Related for CVE-2021-3329