CVE-2023-2683: Connection update while closing connection may lead to denial-of-service
A memory leak in the EFR32 Bluetooth LE stack 5.1.0 through 5.1.1 allows an attacker to send an invalid pairing message and cause future legitimate connection attempts to fail. A reset of the device immediately clears the error.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-2683?
CVE-2023-2683 is a vulnerability in the EFR32 Bluetooth LE stack 5.1.0 through 5.1.1 that allows an attacker to send an invalid pairing message and cause future legitimate connection attempts to fail.
How does CVE-2023-2683 affect the EFR32 Bluetooth LE stack?
CVE-2023-2683 affects the EFR32 Bluetooth LE stack 5.1.0 through 5.1.1 by causing a memory leak when an attacker sends an invalid pairing message.
What is the severity of CVE-2023-2683?
The severity of CVE-2023-2683 is medium with a CVSS score of 6.5.
How can an attacker exploit CVE-2023-2683?
An attacker can exploit CVE-2023-2683 by sending an invalid pairing message to the EFR32 Bluetooth LE stack 5.1.0 through 5.1.1.
How can the memory leak caused by CVE-2023-2683 be cleared?
The memory leak caused by CVE-2023-2683 can be cleared by resetting the affected device.