CVE-2023-6749: Unchecked user input length in the Zephyr Settings Shell
Published Feb 18, 2024
·Updated
Unchecked length coming from user input in settings shell
Affected Software
2 affected components
Zephyr Settings Shell
zephyrproject zephyr<=3.5.0
Remediation
Event History
Feb 18, 2024
CVE Published
via MITRE·07:04 AM
Data Sourced
via MITRE·07:04 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-6749?
The severity of CVE-2023-6749 is currently rated as moderate due to potential denial of service or data corruption risks.
2
How do I fix CVE-2023-6749?
To fix CVE-2023-6749, ensure to validate and sanitize user input length in the Zephyr Settings Shell before processing.
3
Which versions of Zephyr are affected by CVE-2023-6749?
CVE-2023-6749 affects all versions of Zephyr up to and including version 3.5.0.
4
Can CVE-2023-6749 lead to exploits in the system?
Yes, CVE-2023-6749 can potentially be exploited to cause unexpected behavior in applications using the affected software.
5
Is there a public advisory for CVE-2023-6749?
Yes, details regarding CVE-2023-6749, including fixes and affected versions, can be found in the public advisory on the Zephyr project's security page.