CVE-2023-2683

A memory leak in the EFR32 Bluetooth LE stack 5.1.0 through 5.1.1 allows an attacker to send an invalid pairing message and cause future legitimate connection attempts to fail. A reset of the device immediately clears the error.
Configurations

Configuration 1 (hide)

cpe:2.3:a:silabs:bluetooth_low_energy_software_development_kit:*:*:*:*:*:*:*:*

History

21 Nov 2024, 07:59

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 6.5
v2 : unknown
v3 : 5.3
References () https://github.com/SiliconLabs - Not Applicable () https://github.com/SiliconLabs - Not Applicable
References () https://https://siliconlabs.lightning.force.com/sfc/servlet.shepherd/document/download/0698Y00000U2U1QQAV?operationContext=S1 - Broken Link () https://https://siliconlabs.lightning.force.com/sfc/servlet.shepherd/document/download/0698Y00000U2U1QQAV?operationContext=S1 - Broken Link

25 Sep 2024, 17:15

Type Values Removed Values Added
Summary (en) A memory leak in the EFR32 Bluetooth LE stack 5.1.0 through 5.1.1 allows an attacker to send an invalid pairing message and cause future legitimate connection attempts to fail. A reset of the device immediately clears the error. (en) A memory leak in the EFR32 Bluetooth LE stack 5.1.0 through 5.1.1 allows an attacker to send an invalid pairing message and cause future legitimate connection attempts to fail. A reset of the device immediately clears the error.
CWE CWE-401

05 Jul 2023, 13:13

Type Values Removed Values Added
References (MISC) https://github.com/SiliconLabs - (MISC) https://github.com/SiliconLabs - Not Applicable
References (MISC) https://https://siliconlabs.lightning.force.com/sfc/servlet.shepherd/document/download/0698Y00000U2U1QQAV?operationContext=S1 - (MISC) https://https://siliconlabs.lightning.force.com/sfc/servlet.shepherd/document/download/0698Y00000U2U1QQAV?operationContext=S1 - Broken Link
CWE CWE-400
CPE cpe:2.3:a:silabs:bluetooth_low_energy_software_development_kit:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
First Time Silabs
Silabs bluetooth Low Energy Software Development Kit

15 Jun 2023, 20:46

Type Values Removed Values Added
New CVE

Information

Published : 2023-06-15 20:15

Updated : 2024-11-21 07:59


NVD link : CVE-2023-2683

Mitre link : CVE-2023-2683

CVE.ORG link : CVE-2023-2683


JSON object : View

Products Affected

silabs

  • bluetooth_low_energy_software_development_kit
CWE
CWE-401

Missing Release of Memory after Effective Lifetime

CWE-400

Uncontrolled Resource Consumption