CVE-2021-3454 describes an Improper Handling of Length Parameter Inconsistency (CWE-130) and Reachable Assertion (CWE-617) vulnerability in Zephyr RTOS versions 2.4.0 and 2.5.0. A truncated L2CAP K-frame can cause an assertion failure, impacting the availability of affected systems. This vulnerability has a CVSS score of 7.5 (HIGH), indicating a network-based attack with low complexity, requiring no user interaction or privileges, and primarily impacting availability. While it is not currently listed on the KEV catalog or Hot List, its EPSS score is low, suggesting a low likelihood of exploitation. There is no public exploit code available for this vulnerability in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage are minimal, with only one article from BleepingComputer mentioning it.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.4.0, < 2.6.0CPE matchmatch criteria | cpe:2.3:o:zephyrproject:zephyr:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.