Vulnerabilities
Vulnerable Software
Zephyrproject:  Security Vulnerabilities
BT:Classic: Multiple missing buf length checks
CVSS Score
7.6
EPSS Score
0.001
Published
2024-09-13
BT: Classic: SDP OOB access in get_att_search_list
CVSS Score
7.6
EPSS Score
0.001
Published
2024-09-13
BT: Encryption procedure host vulnerability
CVSS Score
8.2
EPSS Score
0.0
Published
2024-09-13
BT: Missing length checks of net_buf in rfcomm_handle_data
CVSS Score
6.8
EPSS Score
0.001
Published
2024-09-13
BT: Missing Check in LL_CONNECTION_UPDATE_IND Packet Leads to Division by Zero
CVSS Score
7.6
EPSS Score
0.001
Published
2024-08-19
A malicious BLE device can send a specific order of packet sequence to cause a DoS attack on the victim BLE device
CVSS Score
6.5
EPSS Score
0.001
Published
2024-07-03
An malicious BLE device can crash BLE victim device by sending malformed gatt packet
CVSS Score
6.8
EPSS Score
0.002
Published
2024-03-29
Zephyr OS IP packet handling does not properly drop IP packets arriving on an external interface with a source address equal to 127.0.01 or the destination address.
CVSS Score
8.6
EPSS Score
0.002
Published
2024-03-15
Possible buffer overflow in is_mount_point
CVSS Score
7.3
EPSS Score
0.003
Published
2024-02-29
The documentation specifies that the BT_GATT_PERM_READ_LESC and BT_GATT_PERM_WRITE_LESC defines for a Bluetooth characteristic: Attribute read/write permission with LE Secure Connection encryption. If set, requires that LE Secure Connections is used for read/write access, however this is only true when it is combined with other permissions, namely BT_GATT_PERM_READ_ENCRYPT/BT_GATT_PERM_READ_AUTHEN (for read) or BT_GATT_PERM_WRITE_ENCRYPT/BT_GATT_PERM_WRITE_AUTHEN (for write), if these additional permissions are not set (even in secure connections only mode) then the stack does not perform any permission checks on these characteristics and they can be freely written/read.
CVSS Score
8.2
EPSS Score
0.002
Published
2024-02-19


Contact Us

Shodan ® - All rights reserved