Lucene search

K
cveZephyrCVE-2023-0396
HistoryJan 25, 2023 - 2:02 a.m.

CVE-2023-0396

2023-01-2502:02:06
CWE-126
CWE-125
zephyr
web.nvd.nist.gov
37
cve-2023-0396
bluetooth
buffer overreads
hci command
nvd

CVSS3

6.8

Attack Vector

PHYSICAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

6.8

Confidence

High

EPSS

0.001

Percentile

35.2%

A malicious / defective bluetooth controller can cause buffer overreads in the most functions that process HCI command responses.

Affected configurations

Nvd
Node
zephyrprojectzephyrRange3.2.0
VendorProductVersionCPE
zephyrprojectzephyr*cpe:2.3:o:zephyrproject:zephyr:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "zephyrproject-rtos",
    "product": "zephyr",
    "versions": [
      {
        "version": "unspecified",
        "lessThanOrEqual": "v3.2",
        "status": "affected",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

6.8

Attack Vector

PHYSICAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

6.8

Confidence

High

EPSS

0.001

Percentile

35.2%

Related for CVE-2023-0396