7.5

CVE-2021-3510

Zephyr JSON decoder incorrectly decodes array of array. Zephyr versions >= >1.14.0, >= >2.5.0 contain Attempt to Access Child of a Non-structure Pointer (CWE-588). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-289f-7mw3-2qf4

Data is provided by the National Vulnerability Database (NVD)
ZephyrprojectZephyr Version1.14.0 Update-
ZephyrprojectZephyr Version1.14.0 Updaterc1
ZephyrprojectZephyr Version1.14.0 Updaterc2
ZephyrprojectZephyr Version1.14.0 Updaterc3
ZephyrprojectZephyr Version1.14.1 Update-
ZephyrprojectZephyr Version1.14.1 Updaterc1
ZephyrprojectZephyr Version1.14.1 Updaterc2
ZephyrprojectZephyr Version1.14.1 Updaterc3
ZephyrprojectZephyr Version1.14.2
ZephyrprojectZephyr Version1.14.3 Updaterc1
ZephyrprojectZephyr Version1.14.3 Updaterc2
ZephyrprojectZephyr Version2.5.0 Update-
ZephyrprojectZephyr Version2.5.0 Updaterc1
ZephyrprojectZephyr Version2.5.0 Updaterc2
ZephyrprojectZephyr Version2.5.0 Updaterc3
ZephyrprojectZephyr Version2.5.0 Updaterc4
ZephyrprojectZephyr Version2.5.1 Updaterc1
ZephyrprojectZephyr Version2.6.0 Update-
ZephyrprojectZephyr Version2.6.0 Updaterc1
ZephyrprojectZephyr Version2.6.0 Updaterc2
ZephyrprojectZephyr Version2.6.0 Updaterc3
ZephyrprojectZephyr Version2.6.1 Updaterc1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.33% 0.533
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
vulnerabilities@zephyrproject.org 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-588 Attempt to Access Child of a Non-structure Pointer

Casting a non-structure type to a structure type and accessing a field can lead to memory access errors or data corruption.