CVE-2023-3725
CVSS 3.1 Score 7.0 of 10 (high)
Details
Summary
CVE-2023-3725 is a newly identified vulnerability that puts at risk the Zephyr CAN bus subsystem. This issue may lead to a buffer overflow, which could potentially be exploited by an attacker to execute arbitrary code or cause a system crash. The Zephyr project is an open-source operating system for various Internet of Things (IoT) devices, and this subsystem is responsible for managing Controller Area Network (CAN) communication. Users of devices running this operating system are advised to update their software as soon as a patch becomes available to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- Unity Technologies