Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Raoul Scholtes

#13724of 53,635
19.6Total CVSS
Vulnerabilities · 2
Critical
2
PT-2023-20496
9.8
2023-03-09
Unknown · Node-Bluetooth-Serial-Port · CVE-2023-26109
**Name of the Vulnerable Software and Affected Versions** node-bluetooth-serial-port versions all **Description** The issue is related to a Buffer Overflow vulnerability via the `findSerialPortChannel` method due to improper user input length validation. This allows for potential exploitation. No information is provided about the estimated number of potentially affected devices worldwide or real-world incidents where this issue was exploited. **Recommendations** For all versions, consider disabling the `findSerialPortChannel` method until a patch is available to prevent potential exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2023-20497
9.8
2023-03-09
Unknown · Node-Bluetooth · CVE-2023-26110
**Name of the Vulnerable Software and Affected Versions** node-bluetooth versions all **Description** The issue arises from improper user input length validation, leading to a Buffer Overflow via the `findSerialPortChannel` method. **Recommendations** For all versions, as a temporary workaround, consider disabling the `findSerialPortChannel` method until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.