Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-45434

Опубликовано: 12 сент. 2025
Источник: nvd
CVSS3: 9.8
EPSS Низкий

Описание

OpenSynergy BlueSDK (aka Blue SDK) through 6.x has a Use-After-Free. The specific flaw exists within the BlueSDK Bluetooth stack. The issue results from the lack of validating the existence of an object before performing operations on the object (aka use after free). An attacker can leverage this to achieve remote code execution in the context of a user account under which the Bluetooth process runs.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:opensynergy:blue_sdk:*:*:*:*:*:*:*:*
Версия до 6.0.1 (включая)

EPSS

Процентиль: 92%
0.05929
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-416

Связанные уязвимости

CVSS3: 9.8
github
12 месяцев назад

OpenSynergy BlueSDK (aka Blue SDK) through 6.x has a Use-After-Free. The specific flaw exists within the BlueSDK Bluetooth stack. The issue results from the lack of validating the existence of an object before performing operations on the object (aka use after free). An attacker can leverage this to achieve remote code execution in the context of a user account under which the Bluetooth process runs.

CVSS3: 8
fstec
около 1 года назад

Уязвимость стека Bluetooth-протоколов OpenSynergy BlueSDK, позволяющая нарушителю выполнить произвольный код и вызвать отказ в обслуживании

EPSS

Процентиль: 92%
0.05929
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-416