PT-2023-13023 · Bestechnic · Bestechnic Bluetooth Mesh Sdk

CVE-2022-30904

·

Publicado

2023-02-01

·

Atualizado

2023-02-09

CVSS v3.1

8.8

Alta

VetorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Bestechnic Bluetooth Mesh SDK (BES2300) version 1.0
Description A buffer overflow issue can be triggered during provisioning due to the lack of a check for the SegN field of the Transaction Start PDU. This occurs because there is no validation for the SegN field, leading to a potential overflow.
Recommendations For Bestechnic Bluetooth Mesh SDK (BES2300) version 1.0, as a temporary workaround, consider implementing a check for the SegN field of the Transaction Start PDU to prevent the buffer overflow. However, at the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Correção

Memory Corruption

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2022-30904

Produtos afetados

Bestechnic Bluetooth Mesh Sdk