Impact
The vulnerability stems from an integer underflow in the MCUmgr SMP‑over‑console transport when decoding a base64 frame. A malicious 7‑byte input causes the packet length to be reduced by two bytes, yielding an inflated length of roughly 65 KB while the actual buffer contains only 384 bytes. This miscalculation allows the CBOR parser to read beyond the allocated buffer, resulting in an out‑of‑bounds read that may lead to a denial of service or exposure of adjacent memory. As the console transport is unauthenticated, the attacker only needs write access to the device’s console, which on many boards is a USB CDC‑ACM interface, to trigger the flaw.
Affected Systems
The flaw is present in Zephyr RTOS releases that build the MCUmgr serial transport with CONFIG_MCUMGR_TRANSPORT_SERIAL_HAS_SMP_OVER_CONSOLE enabled, such as the UART (smp_uart.c) and shell (smp_shell.c) modules. Devices that expose a writable console on their USB CDC‑ACM or UART port are susceptible, and the vulnerability applies to all Zephyr versions prior to the patch commit f7fc3e779a59c68c96eaf63a6b03ac7489f5e4a5.
Risk and Exploitability
The CVSS score of 6.8 indicates a medium severity flaw. EPSS data is not available, and the CVE is not listed in the CISA KEV catalog, suggesting that no public exploitation has been reported. The attack vector is local, requiring an unauthenticated session on the console. An attacker can send the crafted frame to trigger the underflow, read arbitrary memory or crash the MCUmgr thread, creating a denial of service. Because the exploit can be performed with no credentials, the risk to systems with exposed consoles is significant.
OpenCVE Enrichment