CVE-2023-0779Improper Input Validation in Zephyr

Severity
7.7HIGHNVD
CNA6.7
EPSS
0.3%
top 47.91%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 30

Description

At the most basic level, an invalid pointer can be input that crashes the device, but with more knowledge of the device’s memory layout, further exploitation is possible.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:HExploitability: 2.2 | Impact: 5.5

Affected Packages2 packages

CVEListV5zephyrproject-rtos/zephyrunspecifiedv3.3+1

🔴Vulnerability Details

1
CVEList
net: shell: Improper input validation2023-05-30
CVE-2023-0779 — Improper Input Validation in Zephyr | cvebase