CVE-2024-6444
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Published Oct 4, 2024
Updated: Nov 13, 2024
CWE ID 122
CWE ID 787
Summary
CVE-2024-6444 is a newly disclosed vulnerability affecting the Zephyr Project's Bluetooth OTS client. The issue lies in the olcp_ind_handler function within ots_client.c, where user input is not adequately validated for length. This flaw can potentially lead to a buffer overflow, enabling attackers to execute arbitrary code or cause a denial-of-service condition. Users are advised to update their systems as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Zephyrproject Zephyr
Affected Vendors
- Zephyr Project