First published: Fri Mar 29 2024(Updated: )
An malicious BLE device can crash BLE victim device by sending malformed gatt packet
Credit: vulnerabilities@zephyrproject.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zephyr Project Manager | <=3.6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-3077 is classified as a critical vulnerability due to its potential to cause denial of service through a crash of the affected device.
CVE-2024-3077 allows a malicious BLE device to send malformed GATT packets that can crash a vulnerable BLE victim device.
CVE-2024-3077 affects Zephyr versions up to and including 3.6.0.
To mitigate CVE-2024-3077, it is recommended to upgrade to a fixed version of Zephyr beyond 3.6.0.
If your device is affected by CVE-2024-3077, you should immediately review upgrade options to a secure version of Zephyr.