VulnerabilityAnalyzed
CVE-2024-45433
An attacker can leverage this to bypass a security validation and make the incoming data be processed.
MEDIUM 6.5EPSS 0.56%
Does this matter?
Lower severity and a low EPSS score (0.56%). Track it; it rarely justifies an emergency change on its own.
Description
OpenSynergy BlueSDK (aka Blue SDK) through 6.x has Incorrect Control Flow Scoping. The specific flaw exists within the BlueSDK Bluetooth stack. The issue results from the lack of proper return control flow after detecting an unusual condition. An attacker can leverage this to bypass a security validation and make the incoming data be processed.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
- EPSS
- 0.56% probability · 45th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-705
- Affected
- opensynergy/blue sdk
- Source
- cve@mitre.org
References
- https://pcacybersecurity.com/resources/advisory/perfekt-blueExploit, Third Party Advisory
- https://www.opensynergy.com/Product
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.