CVE Feed

    Dashboard / CVE / CVE-2024-48986

    CVE-2024-48986

    An issue was discovered in MBed OS 6.16.0. Its hci parsing software dynamically determines the length of certain hci packets by reading a byte from its header. Certain events cause a callback, the logic for which allocates a buffer (the length of which is determined by looking up the event type in a table). The subsequent write operation, however, copies the amount of data specified in the packet header, which may lead to a buffer overflow. This bug is trivial to exploit for a denial of service but is not certain to suffice to bring the system down and can generally not be exploited further because the exploitable buffer is dynamically allocated.

    Published:Nov 20, 2024
    Last Modified:Nov 26, 2024
    EPS:Nov 20, 2024
    EPSS Score:0.00539
    CVSS Score:7.5

    Affected Products

    Vendor
    Arm
    Product
    Mbed
    Vendor
    Mbed
    Product
    Mbed

    Exploits

    No exploit reference

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High