CVE-2023-3725: Potential buffer overflow vulnerability in the Zephyr CANbus subsystem

7.6 CVSS

Description

Potential buffer overflow vulnerability in the Zephyr CAN bus subsystem

Classification

CVE ID: CVE-2023-3725

CVSS Base Severity: HIGH

CVSS Base Score: 7.6

Affected Products

Vendor: zephyrproject-rtos

Product: Zephyr

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.15% (probability of being exploited)

EPSS Percentile: 51.29% (scored less or equal to compared to others)

EPSS Date: 2025-02-03 (when was this score calculated)

References

https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-2g3m-p6c7-8rr3
http://www.openwall.com/lists/oss-security/2023/11/07/1
http://seclists.org/fulldisclosure/2023/Nov/1
http://packetstormsecurity.com/files/175657/Zephyr-RTOS-3.x.0-Buffer-Overflows.html

Timeline