Impact
A malformed extended advertisement triggers a buffer overflow in the Bluetooth Mesh SDK when parsing advertisements. The overflow results in an out‑of‑bounds write on the stack, corrupting control data and allowing an attacker to execute arbitrary code. This vulnerability arises from unchecked buffer sizes typical of CWE‑130.
Affected Systems
Silicon Labs Bluetooth Mesh SDK version 6.1.4 and all earlier releases are vulnerable. Only devices that serve as provisioners and accept extended advertisements are affected, and the malicious packet must originate from a device that has already joined the mesh network.
Risk and Exploitability
The flaw carries a CVSS score of 8.9, indicating high severity. No EPSS score is available and the vulnerability is not listed in the CISA KEV catalog. An attacker would need to transmit a crafted extended advertisement to a joined provisioner, exploiting the stack corruption to achieve remote code execution. The lack of a publicly stated workaround makes the risk actionable for affected deployments.
OpenCVE Enrichment