Vulnerabilities in zephyrproject-rtos

127 results
Vexday analysis

O ecossistema Zephyr RTOS acumula 130 CVEs catalogadas, das quais 13 são de severidade crítica e 13 surgiram nos últimos 90 dias, indicando um ritmo de descoberta que merece acompanhamento contínuo, especialmente em ambientes embarcados onde ciclos de atualização tendem a ser mais longos. A taxa de exploração ativa está abaixo da média geral do catálogo, com zero entradas no CISA KEV e EPSS máximo de 0,034, sugerindo baixo interesse de agentes de ameaça no momento — embora isso não elimine o risco operacional. O tipo de falha mais prevalente é CWE-120 (buffer overflow clássico), historicamente associado a impactos de alta gravidade em sistemas com restrições de memória, como os alvos típicos do Zephyr. A CVE mais relevante no momento é CVE-2020-10071, que, combinada à existência de pelo menos um PoC público no conjunto total, reforça a necessidade de validar patches aplicados e monitorar a superfície de ataque em dispositivos IoT e sistemas embarcados baseados nesta plataforma.

CVE-2022-0553MEDIUMPossible to retrieve uncrypted firmware imageEPSS 0.3%CVE-2026-5589MEDIUMOut-of-bounds write caused by an integer underflow in the Bluetooth Mesh subsystem.EPSS 0.3%CVE-2026-1677MEDIUMnet: TLS 1.2 connections allowed on TLS 1.3 socketsEPSS 0.2%CVE-2020-13598MEDIUMFS: Buffer Overflow when enabling Long File Names in FAT_FS and calling fs_statEPSS 0.2%CVE-2026-0849LOWcrypto: ATAES132A response length allows stack buffer overflowEPSS 0.2%CVE-2020-13600HIGHMalformed SPI in response for eswifi can corrupt kernel memoryEPSS 0.2%CVE-2020-13603MEDIUMInteger Overflow in memory allocating functionsEPSS 0.2%CVE-2020-13599LOWSecurity problem with settings and littlefsEPSS 0.2%CVE-2021-3435MEDIUML2CAP: Information leakage in le_ecred_conn_req()EPSS 0.2%CVE-2026-1679HIGHnet: eswifi socket send payload length not boundedEPSS 0.2%CVE-2020-10066LOWIncorrect Error Handling in Bluetooth HCI coreEPSS 0.2%CVE-2021-3433MEDIUMBT: Invalid channel map in CONNECT_IND results to DeadlockEPSS 0.2%CVE-2025-9557HIGHBluetooth: Mesh: Out-of-Bound Write in gen_prov_contEPSS 0.2%CVE-2021-3434MEDIUML2CAP: Stack based buffer overflow in le_ecred_conn_req()EPSS 0.2%CVE-2020-10072MEDIUMImproper Handling of Insufficient Permissions or Privileges in zephyrEPSS 0.2%CVE-2026-5590MEDIUMnet: ip/tcp: Null pointer dereference can be triggered by a race conditionEPSS 0.2%CVE-2025-10458HIGHBluetooth: le_conn_rsp does not sanitize CID, MTU, MPS valuesEPSS 0.2%CVE-2025-10456HIGHBluetooth: Semi-Arbitrary ability to make the BLE Target send disconnection requestsEPSS 0.2%CVE-2025-7403HIGHBluetooth: bt_conn_tx_processor unsafe handlingEPSS 0.2%CVE-2025-12890MEDIUMBluetooth: peripheral: Invalid handling of malformed connection requestEPSS 0.2%