PT-2024-23613 · Unknown · Zephyr Rtos

·

CVE-2024-3077

·

Published

2024-03-28

·

Updated

2024-04-05

CVSS v3.1

6.8

Medium

VectorAV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H
Name of the Vulnerable Software and Affected Versions Zephyr RTOS versions prior to 3.6
Description The issue allows a malicious BLE device to crash a BLE victim device by sending a malformed gatt packet. This can be exploited for local attacks. Network segmentation can help mitigate the risk until an update is applied.
Recommendations For Zephyr RTOS versions prior to 3.6, patch or upgrade immediately to prevent local attacks. Ensure network segmentation to mitigate risk until updated. As a temporary workaround, consider restricting access to BLE devices to minimize the risk of exploitation.

Exploit

Fix

Buffer Over-read

Integer Underflow

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-3077
GHSA-GMFV-4VFH-2MH8

Affected Products

Zephyr Rtos