6.4
CVSSv2

CVE-2021-3436

Published: 05/10/2021 Updated: 13/10/2021
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
CVSS v3 Base Score: 6.5 | Impact Score: 2.5 | Exploitability Score: 3.9
VMScore: 570
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:P

Vulnerability Summary

BT: Possible to overwrite an existing bond during keys distribution phase when the identity address of the bond is known. Zephyr versions >= 1.14.2, >= 2.4.0, >= 2.5.0 contain Use of Multiple Resources with Duplicate Identifier (CWE-694). For more information, see github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-j76f-35mc-4h63

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

zephyrproject zephyr 1.14.2

zephyrproject zephyr 2.4.0

zephyrproject zephyr 2.5.0