CVE-2024-6444

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Oct 4, 2024
Updated: Nov 13, 2024
CWE ID 122
CWE ID 787

Summary

CVE-2024-6444 is a newly disclosed vulnerability affecting the Zephyr Project's Bluetooth OTS client. The issue lies in the olcp_ind_handler function within ots_client.c, where user input is not adequately validated for length. This flaw can potentially lead to a buffer overflow, enabling attackers to execute arbitrary code or cause a denial-of-service condition. Users are advised to update their systems as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Zephyrproject Zephyr

Affected Vendors

  • Zephyr Project