PT-2024-15189 · Zephyr Os · Zephyr Os

·

CVE-2023-7060

·

Published

2024-03-15

·

Updated

2025-02-03

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
Name of the Vulnerable Software and Affected Versions Zephyr OS (affected versions not specified)
Description The issue concerns the handling of IP packets in Zephyr OS. Specifically, it does not properly drop IP packets arriving on an external interface with a source address equal to 127.0.0.1 or the destination address. This could potentially lead to security issues, although specific details about the estimated number of affected devices or real-world incidents are not provided.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-7060
GHSA-FJC8-223C-QGQR

Affected Products

Zephyr Os