Unchecked user input length in the Zephyr Settings Shell
CVE-2023-6749

9.8CRITICAL

Key Information:

Status
Vendor
CVE Published:
18 February 2024

What is CVE-2023-6749?

A vulnerability exists in the Zephyr RTOS that pertains to improper validation of input length from user settings. This flaw could potentially allow an attacker to exploit the system by providing specially crafted inputs, leading to unexpected behaviors or potential system compromise. The issue highlights the importance of rigorous input validation mechanisms to safeguard against unauthorized access and maintain the integrity of the system.

Affected Version(s)

Zephyr * <= 3.5

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.