CVE-2021-3436
BT: Possible to overwrite an existing bond during keys distribution phase when the identity address of the bond is known. Zephyr versions >= 1.14.2, >= 2.4.0, >= 2.5.0 contain Use of Multiple Resources with Duplicate Identifier (CWE-694). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-j76f-35mc-4h63
Scoring
- Severity
- MEDIUM
- CVSS base score
- 4.3
- CVSS vector
- CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
- EPSS probability
- 0.32%
- CWE
- CWE-694
- Published
- 2021-10-05
- Last modified
- 2026-03-13
Affected products
- zephyrproject-rtos zephyr
- zephyrproject-rtos zephyr
- zephyrproject-rtos zephyr
Weakness type
Related vulnerabilities
- CVE-2026-71327 — Traefik: Gateway API route identity collision allows cross-namespace backend hijacking
- CVE-2026-57024 — Junos OS: MX with SPC3, SRX Series: Repeated VPN negotiation failures will eventually cause iked to crash continuously
- CVE-2026-5794 — Vulnerability in Cryptobox allows an authenticated user to trigger an account lockout
- CVE-2025-13609 — Keylime: keylime: registrar allows identity takeover via duplicate uuid registration
- CVE-2025-59048 — OpenBao AWS Plugin Vulnerable to Cross-Account IAM Role Impersonation in AWS Auth Method
- CVE-2024-41146 — Use of Multiple Resources with Duplicate Identifier (CWE-694) in the Controller 6000 and Controller...
- CVE-2022-23721 — PingID integration for Windows login duplicate username collision.
- CVE-2023-20100 — Cisco IOS XE Software for Wireless LAN Controllers CAPWAP Join Denial of Service Vulnerability