7.5
CVSSv2

CVE-2021-3625

Published: 05/10/2021 Updated: 13/10/2021
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Buffer overflow in Zephyr USB DFU DNLOAD. Zephyr versions >= v2.5.0 contain Heap-based Buffer Overflow (CWE-122). For more information, see github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-c3gr-hgvr-f363

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

zephyrproject zephyr

Github Repositories

CVE-2021-3625 - Sample exploits for Zephyr

CVE-2021-3625 This repository contains a few example exploits for CVE-2021-3625 All Zephyr-based usb devices up to (and including) version 250 suffer from a buffer overflow allowing readout of up to 65kB Depending on the actual device this may result of leakage of sensitive data like encryption keys or credentials The issue may be triggered by issuing crafted usb control t