Vulnerability Description
There is an error in the condition of the last if-statement in the function smp_check_keys. It was rejecting current keys if all requirements were unmet.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Zephyrproject | Zephyr | <= 3.1.0 |
Related Weaknesses (CWE)
References
- https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-3286-jgjx-MitigationThird Party Advisory
- https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-3286-jgjx-MitigationThird Party Advisory
FAQ
What is CVE-2022-2993?
CVE-2022-2993 is a vulnerability with a CVSS score of 8.6 (HIGH). There is an error in the condition of the last if-statement in the function smp_check_keys. It was rejecting current keys if all requirements were unmet.
How severe is CVE-2022-2993?
CVE-2022-2993 has been rated HIGH with a CVSS base score of 8.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-2993?
Check the references section above for vendor advisories and patch information. Affected products include: Zephyrproject Zephyr.