CVE-2023-0775: Bluetooth LE Invalid prepare write request command leads to denial of service
Published Mar 28, 2023
·Updated
An invalid ‘prepare write request’ command can cause the Bluetooth LE stack to run out of memory and fail to be able to handle subsequent connection requests, resulting in a denial-of-service.
Affected Software
2 affected components
Silabs Gecko Software Development Kit=5.1.0
Silabs Gecko Software Development Kit=5.1.1
Event History
Mar 28, 2023
CVE Published
via MITRE·04:23 PM
Data Sourced
via MITRE·04:23 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID is CVE-2023-0775.
2
What is the severity of CVE-2023-0775?
The severity of CVE-2023-0775 is medium (6.5).
3
What is the affected software for CVE-2023-0775?
The affected software for CVE-2023-0775 is Silabs Gecko Software Development Kit version 5.1.0 and 5.1.1.
4
How does CVE-2023-0775 impact the system?
CVE-2023-0775 can cause the Bluetooth LE stack to run out of memory and fail to handle subsequent connection requests, resulting in a denial-of-service.
5
Is there a fix available for CVE-2023-0775?
Please refer to the official references for updates and patches to fix CVE-2023-0775.