CVE-2024-7137
Estado: AplazadaMedia (6.5)—
The L2CAP receive data buffer for L2CAP packets is restricted to packet sizes smaller than the maximum supported packet size. Receiving a packet that exceeds the restricted buffer length may cause a crash. A hard reset is required to recover the crashed device.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Puntuación base: 6.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.33%
- Percentil entre todas las CVEs puntuadas: 23
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
CWE
- CWE-787
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2024-7137",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-7137",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2024-12-24T00:31:30.427035Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "product-security@silabs.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 6.5,
"attackVector": "ADJACENT_NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "product-security@silabs.com",
"affectedData": [
{
"repo": "https://github.com/SiliconLabs/wiseconnect-wifi-bt-sdk",
"vendor": "silabs.com",
"product": "RS9116 Bluetooth SDK",
"versions": [
{
"status": "affected",
"version": "0",
"versionType": "semver",
"lessThanOrEqual": "2.10.4"
}
],
"packageName": "WiSeConnect SDK",
"defaultStatus": "unaffected"
}
]
}
],
"published": "2024-12-19T20:15:07.820",
"references": [
{
"url": "https://community.silabs.com/068Vm00000I5mjD",
"source": "product-security@silabs.com"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "product-security@silabs.com",
"description": [
{
"lang": "en",
"value": "CWE-787"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The L2CAP receive data buffer for L2CAP packets is restricted to packet sizes smaller than the maximum supported packet size. Receiving a packet that exceeds the restricted buffer length may cause a crash. A hard reset is required to recover the crashed device."
},
{
"lang": "es",
"value": "El búfer de datos de recepción L2CAP para paquetes L2CAP está restringido a tamaños de paquete más pequeños que el tamaño máximo de paquete admitido. Recibir un paquete que supere la longitud restringida del búfer puede provocar un bloqueo. Se requiere un reinicio completo para recuperar el dispositivo bloqueado."
}
],
"lastModified": "2026-06-17T08:19:25.807",
"sourceIdentifier": "product-security@silabs.com"
}