Opensynergy develops the Blue SDK, an automotive software platform widely embedded in vehicle infotainment and connectivity systems, where the disclosed vulnerabilities cluster around input validation, access control, control flow scoping, and memory-safety issues endemic to embedded systems development. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Opensynergy over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-45434CRITICAL OpenSynergy BlueSDK (aka Blue SDK) through 6.x has a Use-After-Free. The specific flaw exists within the BlueSDK Bluetooth stack. The issue results from the lack of validating the | Sep 12, 2025 | 9.8 | 36 | NO | NO |
CVE-2024-45432HIGH OpenSynergy BlueSDK (aka Blue SDK) through 6.x mishandles a function call. The specific flaw exists within the BlueSDK Bluetooth stack. The issue results from an incorrect variable | Sep 12, 2025 | 7.5 | 27 | NO | NO |
CVE-2024-45431MEDIUM OpenSynergy BlueSDK (aka Blue SDK) through 6.x has Improper Input Validation. The specific flaw exists within the BlueSDK Bluetooth stack. The issue results from the lack of proper | Sep 12, 2025 | 5.3 | 24 | NO | NO |
CVE-2018-20378HIGH The L2CAP signaling channel implementation and SDP server implementation in OpenSynergy Blue SDK 3.2 through 6.0 allow remote, unauthenticated attackers to execute arbitrary code o | Mar 29, 2019 | 7.5 | 24 | NO | NO |
CVE-2024-45433MEDIUM OpenSynergy BlueSDK (aka Blue SDK) through 6.x has Incorrect Control Flow Scoping. The specific flaw exists within the BlueSDK Bluetooth stack. The issue results from the lack of p | Sep 12, 2025 | 6.5 | 23 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Opensynergy.
Media articles that mention a CVE ID that affects a product developed by Opensynergy — matched by CVE ID, not by vendor name.