Vulnerabilidades em zephyrproject-rtos

127 resultados
Análise Vexday

O ecossistema Zephyr RTOS acumula 130 CVEs catalogadas, das quais 13 são de severidade crítica e 13 surgiram nos últimos 90 dias, indicando um ritmo de descoberta que merece acompanhamento contínuo, especialmente em ambientes embarcados onde ciclos de atualização tendem a ser mais longos. A taxa de exploração ativa está abaixo da média geral do catálogo, com zero entradas no CISA KEV e EPSS máximo de 0,034, sugerindo baixo interesse de agentes de ameaça no momento — embora isso não elimine o risco operacional. O tipo de falha mais prevalente é CWE-120 (buffer overflow clássico), historicamente associado a impactos de alta gravidade em sistemas com restrições de memória, como os alvos típicos do Zephyr. A CVE mais relevante no momento é CVE-2020-10071, que, combinada à existência de pelo menos um PoC público no conjunto total, reforça a necessidade de validar patches aplicados e monitorar a superfície de ataque em dispositivos IoT e sistemas embarcados baseados nesta plataforma.

CVE-2020-10071CRITICALInsufficient publish message length validation in MQTTEPSS 3.4%CVE-2020-10062CRITICALPacket length decoding error in MQTTEPSS 2.9%CVE-2020-10070CRITICALMQTT buffer overflow on receive bufferEPSS 2.9%CVE-2020-10022CRITICALUpdateHub Module Copies a Variable-Size Hash String Into a Fixed-Size ArrayEPSS 2.3%CVE-2021-3625CRITICALBuffer overflow in Zephyr USB DFU DNLOADEPSS 2.3%CVE-2020-10063MEDIUMRemote Denial of Service in CoAP Option Parsing Due To Integer OverflowEPSS 1.8%CVE-2020-10060HIGHUpdateHub Might Dereference An Uninitialized PointerEPSS 1.6%CVE-2020-10059MEDIUMUpdateHub Module Explicitly Disables TLS VerificationEPSS 1.2%CVE-2021-3455MEDIUMDisconnecting L2CAP channel right after invalid ATT request leads freezeEPSS 1.1%CVE-2023-3725HIGHPotential buffer overflow vulnerability in the Zephyr CANbus subsystemEPSS 1.1%CVE-2022-3806CRITICALBluetooth HCI Error Handling Double FreeEPSS 1.0%CVE-2021-3436MEDIUMBT: Possible to overwrite an existing bond during keys distribution phase when the identity address of the bond is knownEPSS 1.0%CVE-2021-3510HIGHZephyr JSON decoder incorrectly decodes array of arrayEPSS 1.0%CVE-2021-3454MEDIUMTruncated L2CAP K-frame causes assertion failureEPSS 0.9%CVE-2020-13601CRITICALPossible read out of bounds in dns readEPSS 0.9%CVE-2021-3323HIGHInteger Underflow in 6LoWPAN IPHC Header Uncompression in ZephyrEPSS 0.9%CVE-2023-4264HIGHPotential buffer overflow vulnerabilities in the Zephyr Bluetooth subsystemEPSS 0.9%CVE-2023-0359MEDIUMipv6: Missing ipv6 nullptr-check in handle_ra_inputEPSS 0.9%CVE-2021-3319MEDIUMDOS: Incorrect 802154 Frame Validation for Omitted Source / Dest AddressesEPSS 0.9%CVE-2023-4257HIGHUnchecked user input length in the Zephyr WiFi shell moduleEPSS 0.9%