Impact
The vulnerability is a classic buffer overflow caused by an unsafe memcpy call in the Continuous Glucose Monitoring Service's Record Access Control Point write handler. An authenticated BLE peer can supply a payload larger than the fixed 20‑byte BSS buffer, causing adjacent memory to be overwritten. The exact consequences are indeterminate because they depend on the layout of the firmware's BSS section, but the overflow could corrupt control data, crash the system, or even allow arbitrary code execution if the overwritten region contains executable pointers or function references.
Affected Systems
This issue affects devices running Nordic Semiconductor ASA's nRF Connect SDK. No specific version ranges are provided, so all current firmware builds that incorporate the affected SDK release are potentially impacted until the overflow is patched or mitigated.
Risk and Exploitability
The CVSS score of 8.7 classifies the flaw as high severity. Because the attacker must first be authenticated to the device, the attack does not rely on broad public exploits, and the EPSS data is not available, the likelihood of exploitation is uncertain but cannot be dismissed. The vulnerability is not listed in the CISA KEV catalog, indicating no known widespread active exploit chains for this specific flaw. Nonetheless, the nature of the overflow and the breadth of memory it can corrupt give attackers a high likelihood of achieving critical impact if they succeed in compromising a related memory area.
OpenCVE Enrichment