CVE-2024-7137
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Published Dec 19, 2024
CWE ID 787
Summary
CVE-2024-7137 is a vulnerability affecting the L2CAP (Logical Link Control and Adaptation Protocol) receive data buffer in certain devices. The buffer is limited to sizes smaller than the maximum supported packet size. Reception of a packet larger than the restricted buffer length can lead to a crash, necessitating a hard reset to recover the device. This issue may expose devices to denial-of-service attacks using oversized L2CAP packets.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.