CVE-2023-2683

A memory leak in the EFR32 Bluetooth LE stack 5.1.0 through 5.1.1 allows an attacker to send an invalid pairing message and cause future legitimate connection attempts to fail. A reset of the device immediately clears the error.
Configurations

Configuration 1 (hide)

cpe:2.3:a:silabs:bluetooth_low_energy_software_development_kit:*:*:*:*:*:*:*:*

History

25 Sep 2024, 17:15

Type Values Removed Values Added
CWE CWE-401
Summary (en) A memory leak in the EFR32 Bluetooth LE stack 5.1.0 through 5.1.1 allows an attacker to send an invalid pairing message and cause future legitimate connection attempts to fail. A reset of the device immediately clears the error. (en) A memory leak in the EFR32 Bluetooth LE stack 5.1.0 through 5.1.1 allows an attacker to send an invalid pairing message and cause future legitimate connection attempts to fail. A reset of the device immediately clears the error.

05 Jul 2023, 13:13

Type Values Removed Values Added
CWE CWE-400
CPE cpe:2.3:a:silabs:bluetooth_low_energy_software_development_kit:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
References (MISC) https://https://siliconlabs.lightning.force.com/sfc/servlet.shepherd/document/download/0698Y00000U2U1QQAV?operationContext=S1 - (MISC) https://https://siliconlabs.lightning.force.com/sfc/servlet.shepherd/document/download/0698Y00000U2U1QQAV?operationContext=S1 - Broken Link
References (MISC) https://github.com/SiliconLabs - (MISC) https://github.com/SiliconLabs - Not Applicable

15 Jun 2023, 20:46

Type Values Removed Values Added
New CVE

Information

Published : 2023-06-15 20:15

Updated : 2024-09-25 17:15


NVD link : CVE-2023-2683

Mitre link : CVE-2023-2683

CVE.ORG link : CVE-2023-2683


JSON object : View

Products Affected

silabs

  • bluetooth_low_energy_software_development_kit
CWE
CWE-400

Uncontrolled Resource Consumption

CWE-401

Missing Release of Memory after Effective Lifetime