PT-2023-20812 · Unknown · Efr32 Bluetooth Le Stack

CVE-2023-2683

·

Publicado

2023-06-15

·

Atualizado

2024-09-25

CVSS v3.1

6.5

Média

VetorAV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions EFR32 Bluetooth LE stack versions 5.1.0 through 5.1.1
Description A memory leak in the EFR32 Bluetooth LE stack allows an attacker to send an invalid pairing message, causing future legitimate connection attempts to fail. The error is immediately cleared upon resetting the device.
Recommendations For versions 5.1.0 through 5.1.1, consider restarting the device after detecting an invalid pairing message to clear the error. As a temporary workaround, restrict the ability for unauthorized devices to send pairing messages to minimize the risk of exploitation.

Correção

Memory Leak

Resource Exhaustion

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-2683

Produtos afetados

Efr32 Bluetooth Le Stack