Vulnerabilities > Zephyrproject > Medium

DATE CVE VULNERABILITY TITLE RISK
2020-05-11 CVE-2020-10059 Improper Certificate Validation vulnerability in Zephyrproject Zephyr 2.1.0/2.2.0
The UpdateHub module disables DTLS peer checking, which allows for a man in the middle attack.
5.8
2020-05-11 CVE-2020-10058 Improper Input Validation vulnerability in Zephyrproject Zephyr 2.1.0
Multiple syscalls in the Kscan subsystem perform insufficient argument validation, allowing code executing in userspace to potentially gain elevated privileges.
local
low complexity
zephyrproject CWE-20
4.6
2020-05-11 CVE-2020-10028 Improper Input Validation vulnerability in Zephyrproject Zephyr 1.14.0/2.1.0
Multiple syscalls with insufficient argument validation See NCC-ZEP-006 This issue affects: zephyrproject-rtos zephyr version 1.14.0 and later versions.
local
low complexity
zephyrproject CWE-20
4.6
2020-05-11 CVE-2020-10023 Classic Buffer Overflow vulnerability in Zephyrproject Zephyr 1.14.1/2.1.0
The shell subsystem contains a buffer overflow, whereby an adversary with physical access to the device is able to cause a memory corruption, resulting in denial of service or possibly code execution within the Zephyr kernel.
local
low complexity
zephyrproject CWE-120
4.6
2020-05-11 CVE-2020-10021 Out-of-bounds Write vulnerability in Zephyrproject Zephyr
Out-of-bounds Write in the USB Mass Storage memoryWrite handler with unaligned Sizes See NCC-ZEP-024, NCC-ZEP-025, NCC-ZEP-026 This issue affects: zephyrproject-rtos zephyr version 1.14.1 and later versions.
local
low complexity
zephyrproject CWE-787
4.6
2020-05-11 CVE-2020-10019 Classic Buffer Overflow vulnerability in Zephyrproject Zephyr
USB DFU has a potential buffer overflow where the requested length (wLength) is not checked against the buffer size.
local
low complexity
zephyrproject CWE-120
4.6
2019-08-29 CVE-2017-14202 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Zephyrproject Zephyr
Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in the shell component of Zephyr allows a serial or telnet connected user to cause a crash, possibly with arbitrary code execution.
local
low complexity
zephyrproject CWE-119
4.6
2019-08-29 CVE-2017-14201 Use After Free vulnerability in Zephyrproject Zephyr
Use After Free vulnerability in the Zephyr shell allows a serial or telnet connected user to cause denial of service, and possibly remote code execution.
local
low complexity
zephyrproject CWE-416
4.6