CVE-2023-3725

CVSS 3.1 Score 7.0 of 10 (high)

Details

Published Oct 6, 2023
Updated: Dec 22, 2023
CWE ID 367

Summary

CVE-2023-3725 is a newly identified vulnerability that puts at risk the Zephyr CAN bus subsystem. This issue may lead to a buffer overflow, which could potentially be exploited by an attacker to execute arbitrary code or cause a system crash. The Zephyr project is an open-source operating system for various Internet of Things (IoT) devices, and this subsystem is responsible for managing Controller Area Network (CAN) communication. Users of devices running this operating system are advised to update their software as soon as a patch becomes available to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share