CVE-2023-0397
A malicious / defect bluetooth controller can cause a Denial of Service due to unchecked input in le_read_buffer_size_complete.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.6
- CVSS vector
- CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:H
- EPSS probability
- 0.09%
- CWE
- CWE-703
- Published
- 2023-01-19
- Last modified
- 2026-03-13
Affected products
- zephyrproject-rtos zephyr
Weakness type
Related vulnerabilities
- CVE-2021-3329 — DOS: Incorrect handling of the initial HCI ACL_MTU handshake packet leads to crash of bluetooth host layer
- CVE-2024-39815 — Vonets WiFi Bridges Improper Check or Handling of Exceptional Conditions
- CVE-2021-23859 — Denial of Service and Authentication Bypass Vulnerability in multiple Bosch products
- CVE-2019-5031 — An exploitable memory corruption vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader, ver
- CVE-2023-5038 — Unauthenticated DoS
- CVE-2022-22265 — An improper check or handling of exceptional conditions in NPU driver prior to SMR Jan-2022 Release 1 allows arbitrary m
- CVE-2024-21525 — All versions of the package node-twain are vulnerable to Improper Check or Handling of Exceptional Conditions due to the
- CVE-2026-20329 — Cisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Defense Software and Secure Firewall Management Center Software Hardening Release - Exceptional Conditions Handling Vulnerabilities