Silicon Labs Bluetooth SDK Vulnerable to Use After Free Attack
CVE-2023-41093

3.1LOW

Key Information:

Vendor
CVE Published:
12 July 2024

What is CVE-2023-41093?

An issue identified in Silicon Labs Bluetooth SDK for 32-bit ARM architecture allows an attacker with precise timing skills to exploit a Use After Free vulnerability. This flaw can let the attacker intercept a limited number of data packets meant for a recipient that has disconnected from the network, raising significant security concerns for applications utilizing this SDK. Affected versions include all Bluetooth SDKs up to version 8.0.0, thereby necessitating timely security measures and updates to mitigate potential exploitation.

Affected Version(s)

Simplicity SDK 32 bit 0 <= 8.0.0

References

CVSS V3.1

Score:
3.1
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.