CVE-2022-35623: High severity NordicSemi Nrf5 Sdk For Mesh vulnerability
Published Aug 15, 2022
·Updated
In Nordic nRF5 SDK for Mesh 5.0, a heap overflow vulnerability can be triggered by sending a series of segmented control packets and access packets with the same SeqAuth
Affected Software
1 affected component
NordicSemi Nrf5 Sdk For Mesh=5.0
Event History
Aug 15, 2022
CVE Published
via MITRE·04:09 PM
Data Sourced
via MITRE·04:09 PM
DescriptionSeverity
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2022-35623.
2
What is the severity of CVE-2022-35623?
The severity of CVE-2022-35623 is high with a CVSS score of 8.8.
3
How does the vulnerability in Nordic nRF5 SDK for Mesh 5.0 occur?
The vulnerability in Nordic nRF5 SDK for Mesh 5.0 occurs due to a heap overflow triggered by sending a series of segmented control packets and access packets with the same SeqAuth.
4
What software is affected by CVE-2022-35623?
The affected software is Nordic nRF5 SDK for Mesh 5.0.
5
How can I fix CVE-2022-35623?
To fix CVE-2022-35623, it is recommended to update to the latest version of Nordic nRF5 SDK for Mesh.