PT-2024-23613 · Unknown · Zephyr Rtos
Xiaobye-Ctf
·
Published
2024-03-28
·
Updated
2024-04-05
·
CVE-2024-3077
CVSS v3.1
6.8
Medium
| Vector | AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H |
Name of the Vulnerable Software and Affected Versions
Zephyr RTOS versions prior to 3.6
Description
The issue allows a malicious BLE device to crash a BLE victim device by sending a malformed gatt packet. This can be exploited for local attacks. Network segmentation can help mitigate the risk until an update is applied.
Recommendations
For Zephyr RTOS versions prior to 3.6, patch or upgrade immediately to prevent local attacks. Ensure network segmentation to mitigate risk until updated. As a temporary workaround, consider restricting access to BLE devices to minimize the risk of exploitation.
Fix
Buffer Over-read
Integer Underflow
Integer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Zephyr Rtos