OpenSynergy BlueSDK (aka Blue SDK) through 6.x has Improper Input Validation. The specific flaw exists within the BlueSDK Bluetooth stack. The issue results from the lack of proper validation of remote L2CAP channel ID (CID). An attacker can leverage this to create an L2CAP channel with the null identifier assigned as a remote CID.
Metrics
Affected Vendors & Products
References
History
Mon, 15 Sep 2025 10:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Opensynergy
Opensynergy blue Sdk |
|
Vendors & Products |
Opensynergy
Opensynergy blue Sdk |
Fri, 12 Sep 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-20 | |
Metrics |
cvssV3_1
|
Fri, 12 Sep 2025 16:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | OpenSynergy BlueSDK (aka Blue SDK) through 6.x has Improper Input Validation. The specific flaw exists within the BlueSDK Bluetooth stack. The issue results from the lack of proper validation of remote L2CAP channel ID (CID). An attacker can leverage this to create an L2CAP channel with the null identifier assigned as a remote CID. | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-09-12T17:29:10.293Z
Reserved: 2024-08-29T00:00:00.000Z
Link: CVE-2024-45431

Updated: 2025-09-12T17:28:59.794Z

Status : Awaiting Analysis
Published: 2025-09-12T17:15:45.850
Modified: 2025-09-15T15:21:42.937
Link: CVE-2024-45431

No data.