CVE-2022-2993

There is an error in the condition of the last if-statement in the function smp_check_keys. It was rejecting current keys if all requirements were unmet.
Configurations

Configuration 1 (hide)

cpe:2.3:o:zephyrproject:zephyr:*:*:*:*:*:*:*:*

History

22 Apr 2025, 18:15

Type Values Removed Values Added
CWE CWE-670

21 Nov 2024, 07:02

Type Values Removed Values Added
References () https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-3286-jgjx-8cvr - Mitigation, Third Party Advisory () https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-3286-jgjx-8cvr - Mitigation, Third Party Advisory
CVSS v2 : unknown
v3 : 9.8
v2 : unknown
v3 : 8.6

12 Dec 2022, 17:12

Type Values Removed Values Added
New CVE

Information

Published : 2022-12-09 20:15

Updated : 2025-04-22 18:15


NVD link : CVE-2022-2993

Mitre link : CVE-2022-2993

CVE.ORG link : CVE-2022-2993


JSON object : View

Products Affected

zephyrproject

  • zephyr
CWE
NVD-CWE-noinfo CWE-670

Always-Incorrect Control Flow Implementation