ARM mbed-os Buffer Overflow Vulnerability Allows Remote Execution of Arbitrary Code
CVE-2024-22905
7HIGH
What is CVE-2024-22905?
A buffer overflow vulnerability exists in ARM mbed-os versions prior to v.6.17.0, allowing remote attackers to inject and execute arbitrary code. This can occur via a crafted script targeting the hciTrSerialRxIncoming function, posing significant risks to device integrity and security in IoT environments. Users are advised to evaluate their deployments and apply necessary updates.