PT-2024-23613 · Unknown · Zephyr Rtos

Xiaobye-Ctf

·

Published

2024-03-28

·

Updated

2024-04-05

·

CVE-2024-3077

CVSS v3.1

6.8

Medium

VectorAV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H
Name of the Vulnerable Software and Affected Versions Zephyr RTOS versions prior to 3.6
Description The issue allows a malicious BLE device to crash a BLE victim device by sending a malformed gatt packet. This can be exploited for local attacks. Network segmentation can help mitigate the risk until an update is applied.
Recommendations For Zephyr RTOS versions prior to 3.6, patch or upgrade immediately to prevent local attacks. Ensure network segmentation to mitigate risk until updated. As a temporary workaround, consider restricting access to BLE devices to minimize the risk of exploitation.

Fix

Buffer Over-read

Integer Underflow

Integer Overflow

Weakness Enumeration

Related Identifiers

CVE-2024-3077
GHSA-GMFV-4VFH-2MH8

Affected Products

Zephyr Rtos