CVE-2023-6387: Incorrect buffer parsing in Bluetooth LE sample code may lead to buffer overflow
Published Feb 2, 2024
·Updated
A potential buffer overflow exists in the Bluetooth LE HCI CPC sample application in the Gecko SDK which may result in a denial of service or remote code execution
Affected Software
1 affected component
Silabs Gecko Software Development Kit<4.4.0
Event History
Feb 2, 2024
CVE Published
via MITRE·03:18 PM
Data Sourced
via MITRE·03:18 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-6387?
CVE-2023-6387 has been classified as a critical vulnerability due to its potential for denial of service and remote code execution.
2
How do I fix CVE-2023-6387?
To remediate CVE-2023-6387, users should upgrade to Silicon Labs Gecko SDK version 4.4.0 or later.
3
What causes CVE-2023-6387?
CVE-2023-6387 is caused by a potential buffer overflow in the Bluetooth LE HCI CPC sample application within the Gecko SDK.
4
Who is affected by CVE-2023-6387?
CVE-2023-6387 affects users of the Silicon Labs Gecko Software Development Kit prior to version 4.4.0.
5
What is the exploitability of CVE-2023-6387?
CVE-2023-6387 is considered highly exploitable, potentially allowing attackers to execute arbitrary code remotely.