First published: Fri Feb 02 2024(Updated: )
A potential buffer overflow exists in the Bluetooth LE HCI CPC sample application in the Gecko SDK which may result in a denial of service or remote code execution
Credit: product-security@silabs.com
Affected Software | Affected Version | How to fix |
---|---|---|
Silicon Labs Gecko SDK | <4.4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-6387 has been classified as a critical vulnerability due to its potential for denial of service and remote code execution.
To remediate CVE-2023-6387, users should upgrade to Silicon Labs Gecko SDK version 4.4.0 or later.
CVE-2023-6387 is caused by a potential buffer overflow in the Bluetooth LE HCI CPC sample application within the Gecko SDK.
CVE-2023-6387 affects users of the Silicon Labs Gecko Software Development Kit prior to version 4.4.0.
CVE-2023-6387 is considered highly exploitable, potentially allowing attackers to execute arbitrary code remotely.