CVE-2022-1041: Out-of-bound write vulnerability in the Bluetooth mesh core stack can be triggered during provisioning
Published Jul 26, 2022
·Updated
In Zephyr bluetooth mesh core stack, an out-of-bound write vulnerability can be triggered during provisioning.
Affected Software
1 affected component
zephyrproject zephyr<=3.0.0
Remediation
Event History
Jul 26, 2022
CVE Published
via MITRE·04:25 AM
Data Sourced
via MITRE·04:25 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2022-1041.
2
What is the title of the vulnerability?
The title of the vulnerability is 'In Zephyr bluetooth mesh core stack an out-of-bound write vulnerability can be triggered during provisioning.'
3
What is the severity of the vulnerability?
The severity of the vulnerability is high with a CVSS score of 8.8.
4
What software is affected by the vulnerability?
The Zephyr bluetooth mesh core stack version up to 3.0.0 is affected by the vulnerability.
5
How can the vulnerability be triggered?
The vulnerability can be triggered during provisioning in the Zephyr bluetooth mesh core stack.