CVE-2023-4257: Unchecked user input length in the Zephyr WiFi shell module

7.6 CVSS

Description

Unchecked user input length in /subsys/net/l2/wifi/wifi_shell.c can cause buffer overflows.

Classification

CVE ID: CVE-2023-4257

CVSS Base Severity: HIGH

CVSS Base Score: 7.6

Affected Products

Vendor: zephyrproject-rtos

Product: Zephyr

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.11% (probability of being exploited)

EPSS Percentile: 45.22% (scored less or equal to compared to others)

EPSS Date: 2025-02-03 (when was this score calculated)

References

https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-853q-q69w-gf5j
http://www.openwall.com/lists/oss-security/2023/11/07/1
http://seclists.org/fulldisclosure/2023/Nov/1
http://packetstormsecurity.com/files/175657/Zephyr-RTOS-3.x.0-Buffer-Overflows.html

Timeline