Aller au contenu

Fiche vulnérabilité

CVE-2022-2741 : faille élevée zephyrproject-rtos zephyr (CVSS 8.2)

Description

The denial-of-service can be triggered by transmitting a carefully crafted CAN frame on the same CAN network as the vulnerable node. The frame must have a CAN ID matching an installed filter in the vulnerable node (this can easily be guessed based on CAN traffic analyses). The frame must contain the opposite RTR bit as what the filter installed in the vulnerable node contains (if the filter matches RTR frames, the frame must be a data frame or vice versa).

En bref

Sévérité
Élevée (CVSS 8.2)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
Exploitation active
Non signalée par la CISA
Publication
31 oct. 2022
Dernière mise à jour
5 mai 2025

Produits concernés

  • zephyrproject-rtos zephyr

Preuves de concept publiques

Code tiers non vérifié : à n’exécuter qu’en environnement isolé.

Références

Rechercher une autre vulnérabilité dans la base CVE