CVE-2023-2234Type Confusion in Zephyr

CWE-843Type Confusion2 documents2 sources
Severity
8.8HIGHNVD
CNA6.8
EPSS
0.0%
top 86.05%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 10

Description

Union variant confusion allows any malicious BT controller to execute arbitrary code on the Zephyr host.

CVSS vector

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages2 packages

CVEListV5zephyrproject-rtos/zephyr*3.3

🔴Vulnerability Details

1
CVEList
BT HCI host union variant confusion2023-07-10
CVE-2023-2234 — Type Confusion in Zephyr | cvebase