CVE-2021-3319CWE-476CWE-588

DOS: Incorrect 802154 Frame Validation for Omitted Source / Dest Addresses

Medium · published October 5, 2021

CVSS v3.1
6.5
EPSS
1%
Percentile
56.8
In the wild
Unconfirmed
What it is

DOS: Incorrect 802154 Frame Validation for Omitted Source / Dest Addresses. Zephyr versions >= > v2.4.0 contain NULL Pointer Dereference (CWE-476), Attempt to Access Child of a Non-structure Pointer (CWE-588). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-94jg-2p6q-5364

The record
Technical detail
CVSS v3.1
6.5 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H
CVSS v4.0
Not supplied
EPSS
0.00880 · 56.8th percentile
Weaknesses
CWE-476 · NULL Pointer Dereference; CWE-588 · Attempt to Access Child of a Non-structure Pointer
Published
2021-10-05T20:50Z
EPSS history
Timeline
  • 05 OCT 20:50Z
    DOS: Incorrect 802154 Frame Validation for Omitted Source / Dest Addresses
    cvelistv5