CVE-2020-15531
HIGH 8.8EPSS 4.0%
Silicon Labs Bluetooth Low Energy SDK before 2.13.3 has a buffer overflow via packet data. This is an over-the-air remote code execution vulnerability in Bluetooth LE in EFR32 SoCs and associated modules running Bluetooth SDK, supporting Central or Observer roles.
- CVSS v3.1
- 8.8 HIGH
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v2.0
- 5.8 MEDIUM
AV:A/AC:L/Au:N/C:P/I:P/A:P - EPSS
- 4.00% chance of exploitation in the next 30 days, 90th percentile
- Published
- 2020-08-19
- Updated
- 2024-08-04
Proof-of-concept exploits (2)
- darkmentorllc/jackbnimble/blob/master/host/pocs/silabs_efr32_extadv_rce.py
- https://www.youtube.com/watch?v=saoTr1NwdzM