Impact
A missing bounds check in the ATT layer write request handler of ArduinoBLE allows a remote unauthenticated BLE client to send a malformed ATT write request that corrupts the global ATTClass instance. The corruption is a buffer‑size relational error and an out‑of‑bounds write, which can lead to arbitrary code execution or device denial of service.
Affected Systems
The vulnerability exists in the ArduinoBLE library for Arduino models that include the library. Devices running versions before 2.0.2, especially those with characteristics configured with the BLEEncryption property, are vulnerable.
Risk and Exploitability
The flaw has a CVSS score of 7.2, a high vulnerability level. The EPSS score of <1% indicates that exploitation attempts are unlikely, although a known attack scenario exists. Because the bug is not yet cataloged in KEV, it has not been widely reported as exploited, but any device that has not updated to 2.0.2 remains at risk of remote code execution through a simple BLE request.
OpenCVE Enrichment