Описание
A vulnerability was identified in the handling of Bluetooth Low Energy (BLE) fixed channels (such as SMP or ATT). Specifically, an attacker could exploit a flaw that causes the BLE target (i.e., the device under attack) to attempt to disconnect a fixed channel, which is not allowed per the Bluetooth specification. This leads to undefined behavior, including potential assertion failures, crashes, or memory corruption, depending on the BLE stack implementation.
Ссылки
- PatchVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 4.1.0 (включая)
cpe:2.3:o:zephyrproject:zephyr:*:*:*:*:*:*:*:*
EPSS
Процентиль: 12%
0.00042
Низкий
7.1 High
CVSS3
6.5 Medium
CVSS3
Дефекты
CWE-190
EPSS
Процентиль: 12%
0.00042
Низкий
7.1 High
CVSS3
6.5 Medium
CVSS3
Дефекты
CWE-190