Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gfw9-vqj5-5mg2

Опубликовано: 12 сент. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

OpenSynergy BlueSDK (aka Blue SDK) through 6.x has a Use-After-Free. The specific flaw exists within the BlueSDK Bluetooth stack. The issue results from the lack of validating the existence of an object before performing operations on the object (aka use after free). An attacker can leverage this to achieve remote code execution in the context of a user account under which the Bluetooth process runs.

OpenSynergy BlueSDK (aka Blue SDK) through 6.x has a Use-After-Free. The specific flaw exists within the BlueSDK Bluetooth stack. The issue results from the lack of validating the existence of an object before performing operations on the object (aka use after free). An attacker can leverage this to achieve remote code execution in the context of a user account under which the Bluetooth process runs.

EPSS

Процентиль: 76%
0.00964
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-416

Связанные уязвимости

CVSS3: 9.8
nvd
5 месяцев назад

OpenSynergy BlueSDK (aka Blue SDK) through 6.x has a Use-After-Free. The specific flaw exists within the BlueSDK Bluetooth stack. The issue results from the lack of validating the existence of an object before performing operations on the object (aka use after free). An attacker can leverage this to achieve remote code execution in the context of a user account under which the Bluetooth process runs.

CVSS3: 8
fstec
7 месяцев назад

Уязвимость стека Bluetooth-протоколов OpenSynergy BlueSDK, позволяющая нарушителю выполнить произвольный код и вызвать отказ в обслуживании

EPSS

Процентиль: 76%
0.00964
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-416