PT-2023-20812 · Unknown · Efr32 Bluetooth Le Stack

Published

2023-06-15

·

Updated

2024-09-25

·

CVE-2023-2683

CVSS v3.1

6.5

Medium

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions EFR32 Bluetooth LE stack versions 5.1.0 through 5.1.1
Description A memory leak in the EFR32 Bluetooth LE stack allows an attacker to send an invalid pairing message, causing future legitimate connection attempts to fail. The error is immediately cleared upon resetting the device.
Recommendations For versions 5.1.0 through 5.1.1, consider restarting the device after detecting an invalid pairing message to clear the error. As a temporary workaround, restrict the ability for unauthorized devices to send pairing messages to minimize the risk of exploitation.

Fix

Memory Leak

Resource Exhaustion

Weakness Enumeration

Related Identifiers

CVE-2023-2683

Affected Products

Efr32 Bluetooth Le Stack