CVE-2023-5184
HIGH 8.8EPSS 0.4%
Two potential signed to unsigned conversion errors and buffer overflow vulnerabilities at the following locations in the Zephyr IPM drivers.
- CVSS v3.1
- 8.8 HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H - CVSS v3.1
- 7.0 HIGH
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:H - EPSS
- 0.39% chance of exploitation in the next 30 days, 32th percentile
- Published
- 2023-09-27
- Updated
- 2025-06-18
Proof-of-concept exploits (2)
- http://packetstormsecurity.com/files/175657/Zephyr-RTOS-3.x.0-Buffer-Overflows.html
- zephyrproject-rtos/zephyr/security/advisories/GHSA-8x3p-q3r5-xh9g