Denial of Service Vulnerability in Silicon Labs Bluetooth Products
CVE-2024-7138

6.5MEDIUM

Key Information:

Vendor

Silabs.com

Vendor
CVE Published:
19 December 2024

What is CVE-2024-7138?

CVE-2024-7138 represents a critical vulnerability in the Silicon Labs Bluetooth stack, where an assert failure may occur when a peer device transmits a specially crafted malformed L2CAP packet. This flaw can lead to a temporary denial of service, requiring a hard reset of the affected device if a watchdog timer is disabled. The vulnerability poses significant security risks for applications relying on Bluetooth connectivity. Immediate action is recommended to mitigate potential disruptions and maintain system integrity.

Affected Version(s)

RS9116 Bluetooth SDK 0 <= 2.10.4

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.