8.8
CVSSv3

CVE-2022-31363

Published: 01/02/2023 Updated: 09/02/2023
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

Cypress : www.infineon.com/ Cypress Bluetooth Mesh SDK BSA0107_05.01.00-BX8-AMESH-08 is affected by: Buffer Overflow. The impact is: execute arbitrary code (remote). The component is: affected function is pb_transport_handle_frag_. ¶¶ In Cypress Bluetooth Mesh SDK, there is an out-of-bound write vulnerability that can be triggered during mesh provisioning. Because there is no check for mismatched SegN and TotalLength in Transaction Start PDU.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

infineon cypress bluetooth mesh software development kit bsa0107_05.01.00-bx8-amesh-08