Improper Discarding in HCI
CVE-2024-6259

7.6HIGH

Key Information:

Status
Vendor
CVE Published:
13 September 2024

What is CVE-2024-6259?

The vulnerability in the Bluetooth Low Energy Stack within the Zephyr Project is characterized by improper handling of the adv_ext_report, which could lead to potential information leaks or unintended behavior during Bluetooth communications. This vulnerability highlights the importance of proper data management in Bluetooth protocols to ensure security and reliability.

Affected Version(s)

Zephyr * <= 3.6

References

CVSS V3.1

Score:
7.6
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.