CVE-2024-48981
Last modified
CVE-2024-48981 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. An issue was discovered in MBed OS 6.16.0. During processing of HCI packets, the software dynamically determines the length of the packet header by looking up the identifying first byte and matching it against a table of possible lengths. EPSS estimates a 0.35% chance of exploitation in the next 30 days.
Description
An issue was discovered in MBed OS 6.16.0. During processing of HCI packets, the software dynamically determines the length of the packet header by looking up the identifying first byte and matching it against a table of possible lengths. The initial parsing function, hciTrSerialRxIncoming does not drop packets with invalid identifiers but also does not set a safe default for the length of unknown packets' headers, leading to a buffer overflow. This can be leveraged into an arbitrary write by an attacker. It is possible to overwrite the pointer to a not-yet-allocated buffer that is supposed to receive the contents of the packet body. One can then overwrite the state variable used by the function to determine which state of packet parsing is currently occurring. Because the buffer is allocated when the last byte of the header has been copied, the combination of having a bad header length variable that will never match the counter variable and being able to overwrite the state variable with the resulting buffer overflow can be used to advance the function to the next step while skipping the buffer allocation and resulting pointer write. The next 16 bytes from the packet body are then written wherever the corrupted data pointer is pointing.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Arm | Mbed | 6.16.0 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2024-48981?
How severe is CVE-2024-48981?
How do I fix CVE-2024-48981?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-4897parisneo/lollms-webui, in its latest version, is vulnerable …8.4
- CVE-2024-48970The ventilator's microcontroller lacks memory protection. An…9.3
- CVE-2024-48971The Clinician Password and Serial Number Clinician Password …9.3
- CVE-2024-48973The debug port on the ventilator's serial interface is enabl…9.3
- CVE-2024-48974The ventilator does not perform proper file integrity checks…9.3
- CVE-2024-4898The InstaWP Connect – 1-click WP Staging & Migration plugin …9.8
- CVE-2024-48982An issue was discovered in MBed OS 6.16.0. Its hci parsing s…7.5
- CVE-2024-48983An issue was discovered in MBed OS 6.16.0. During processing…7.5
- CVE-2024-48984An issue was discovered in MBed OS 6.16.0. When parsing hci …9.8
- CVE-2024-48985An issue was discovered in MBed OS 6.16.0. During processing…7.5
- CVE-2024-48986An issue was discovered in MBed OS 6.16.0. Its hci parsing s…7.5
- CVE-2024-48987Snipe-IT before 7.0.10 allows remote code execution (associa…6.6
Are you affected by CVE-2024-48981?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
