# CVE-2021-3436

## Summary

- **CVE ID:** CVE-2021-3436
- **Severity:** MEDIUM
- **CVSS Score:** 4.3 (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
- **CWE:** CWE-694
- **Published:** Oct 5, 2021
- **Last Modified:** Mar 13, 2026

## Description

BT: Possible to overwrite an existing bond during keys distribution phase when the identity address of the bond is known. Zephyr versions >= 1.14.2, >= 2.4.0, >= 2.5.0 contain Use of Multiple Resources with Duplicate Identifier (CWE-694). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-j76f-35mc-4h63

## Affected Products

- zephyrproject-rtos — zephyr (1.14.2)
- zephyrproject-rtos — zephyr (2.4.0)
- zephyrproject-rtos — zephyr (2.5.0)

## References

- [CNA](http://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-j76f-35mc-4h63)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.32%
- **EPSS Percentile:** 54.2

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._