CVE-2023-4257: Unchecked user input length in the Zephyr WiFi shell module
Published Oct 13, 2023
·Updated
Unchecked user input length in /subsys/net/l2/wifi/wifishell.c can cause buffer overflows.
Affected Software
1 affected component
zephyrproject zephyr<=3.4.0
Event History
Oct 13, 2023
CVE Published
09:09 PM
Data Sourced
09:09 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2023-4257.
2
What is the severity of CVE-2023-4257?
The severity of CVE-2023-4257 is critical with a CVSS score of 9.8.
3
What is the affected software?
The affected software is Zephyrproject Zephyr up to version 3.4.0.
4
What is the impact of this vulnerability?
This vulnerability allows for buffer overflows, which can lead to potential code execution or denial of service attacks.
5
Is there a fix available for this vulnerability?
Yes, a fix is available. Please refer to the vendor's advisory for more information and apply the necessary patches or updates.