CVE-2023-0775 Vulnerability Details

  /     /     /  

CVE-2023-0775 Metadata Quick Info

CVE Published: 28/03/2023 | CVE Updated: 02/08/2024 | CVE Year: 2023
Source: Silabs | Vendor: silabs.com | Product: GSDK
Status : PUBLISHED

CVE-2023-0775 Description

An invalid ‘prepare write request’ command can cause the Bluetooth LE stack to run out of memory and fail to be able to handle subsequent connection requests, resulting in a denial-of-service.

Metrics

CVSS Version: 3.1 | Base Score: 6.5 MEDIUM
Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

l➤ Exploitability Metrics:
    Attack Vector (AV)* ADJACENT_NETWORK
    Attack Complexity (AC)* LOW
    Privileges Required (PR)* NONE
    User Interaction (UI)* NONE
    Scope (S)* UNCHANGED

l➤ Impact Metrics:
    Confidentiality Impact (C)* NONE
    Integrity Impact (I)* NONE
    Availability Impact (A)* HIGH

Weakness Enumeration (CWE)

CWE-ID: CWE-20
CWE Name: CWE-20 Improper Input Validation
Source: silabs.com

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID: CAPEC-123
CAPEC Description: CAPEC-123 Buffer Manipulation


Source: NVD (National Vulnerability Database).