PT-2023-18442 · Zephyr · Zephyr

Scepticz

+1

·

Published

2023-07-10

·

Updated

2023-08-28

·

CVE-2023-2234

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Zephyr (affected versions not specified)
Description The issue allows any malicious Bluetooth controller to execute arbitrary code on the Zephyr host due to union variant confusion.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Type Confusion

Weakness Enumeration

Related Identifiers

CVE-2023-2234
GHSA-FX9G-8FR2-Q899

Affected Products

Zephyr