Impact
A malformed Bluetooth connection request message can trigger the BT122 to leak potentially sensitive information. The flaw originates from improper handling of an increased length field in the packet, leading to a buffer over‑read (CWE‑126). When an attacker sends a crafted request, the device may read memory beyond the requested bounds and expose that data, although there is no evidence of code execution or denial of service. The CVSS score of 5.3 indicates a moderate severity.
Affected Systems
Silabs BT122 transceivers are the affected devices. No specific firmware version is listed in the CVE data, so the vulnerability may affect all available firmware versions until an update is released.
Risk and Exploitability
The EPSS score is not available, so the field‑level exploitation probability cannot be quantified; however, the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a spoofed Bluetooth connection request within range of the device, which would trigger the memory leak. Once triggered, the leaked data could be captured by an attacker with physical or wireless proximity, potentially exposing internal memory contents or configuration data. Because the flaw involves a malformed packet, an attacker does not need privileged access to invoke it, meaning the risk is operational rather than privileged.
OpenCVE Enrichment