Vulnerabilities in zephyrproject-rtos

127 results
Vexday analysis

O ecossistema Zephyr RTOS acumula 130 CVEs catalogadas, das quais 13 são de severidade crítica e 13 surgiram nos últimos 90 dias, indicando um ritmo de descoberta que merece acompanhamento contínuo, especialmente em ambientes embarcados onde ciclos de atualização tendem a ser mais longos. A taxa de exploração ativa está abaixo da média geral do catálogo, com zero entradas no CISA KEV e EPSS máximo de 0,034, sugerindo baixo interesse de agentes de ameaça no momento — embora isso não elimine o risco operacional. O tipo de falha mais prevalente é CWE-120 (buffer overflow clássico), historicamente associado a impactos de alta gravidade em sistemas com restrições de memória, como os alvos típicos do Zephyr. A CVE mais relevante no momento é CVE-2020-10071, que, combinada à existência de pelo menos um PoC público no conjunto total, reforça a necessidade de validar patches aplicados e monitorar a superfície de ataque em dispositivos IoT e sistemas embarcados baseados nesta plataforma.

CVE-2020-10028HIGHMultiple Syscalls In GPIO Subsystem Performs No Argument ValidationEPSS 0.4%CVE-2023-4424HIGHbt: hci: DoS and possible RCEEPSS 0.4%CVE-2023-5184HIGHPotential signed to unsigned conversion errors and buffer overflow vulnerabilities in the Zephyr IPM driverEPSS 0.4%CVE-2020-10069MEDIUMZephyr Bluetooth unchecked packet data results in denial of serviceEPSS 0.4%CVE-2026-1678CRITICALdns: memory‑safety issue in the DNS name parserEPSS 0.4%CVE-2025-1675HIGHOut of bounds read in dns_copy_qnameEPSS 0.4%CVE-2025-10457MEDIUMBluetooth: Out-Of-Context le_conn_rsp HandlingEPSS 0.4%CVE-2025-1674HIGHOut of bounds read when unpacking DNS answersEPSS 0.4%CVE-2024-1638HIGHBluetooth characteristic LESC security requirement not enforced without additional flagsEPSS 0.4%CVE-2021-3581HIGHBuffer Access with Incorrect Length Value in zephyrEPSS 0.3%CVE-2024-6444MEDIUMBluetooth: ots: missing buffer length checkEPSS 0.3%CVE-2025-1673HIGHOut of bounds read when calling crc16_ansi and strlen in dns_validate_msgEPSS 0.3%CVE-2024-6442MEDIUMBluetooth: ASCS Unchecked tailroom of the response bufferEPSS 0.3%CVE-2026-13351HIGHnet: Maliciously fragmented IPv6 packets can prevent receiving/processing future incoming packetsEPSS 0.3%CVE-2026-5066MEDIUMnet: sockets: tls: Potential out-of-bounds write/read in socket_op_vtable::connect functionEPSS 0.3%CVE-2024-5754HIGHBT: Encryption procedure host vulnerabilityEPSS 0.3%CVE-2024-10395HIGHnet: lib: http_server: Buffer Under-readEPSS 0.3%CVE-2025-12899MEDIUMnet: icmp: Out of bound memory readEPSS 0.3%CVE-2026-5072MEDIUMptp: Potential Denial of Service via PTP Interval ShiftEPSS 0.3%CVE-2020-13602MEDIUMRemote Denial of Service in LwM2M do_write_op_tlvEPSS 0.3%