First published: Fri Dec 09 2022(Updated: )
There is an error in the condition of the last if-statement in the function smp_check_keys. It was rejecting current keys if all requirements were unmet.
Credit: vulnerabilities@zephyrproject.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zephyrproject Zephyr | <=3.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-2993.
The severity of CVE-2022-2993 is critical with a CVSS score of 9.8.
The Zephyr Project Zephyr software up to version 3.1.0 is affected by CVE-2022-2993.
CVE-2022-2993 is a vulnerability in the function smp_check_keys, where there is an error in the condition of the last if-statement, causing it to reject current keys if all requirements are unmet.
To fix CVE-2022-2993, it is recommended to update to a version of Zephyr Project Zephyr that is not affected by the vulnerability.