Medium severity4.3NVD Advisory· Published Oct 5, 2021· Updated Jun 17, 2026
CVE-2021-3436
CVE-2021-3436
Description
BT: Possible to overwrite an existing bond during keys distribution phase when the identity address of the bond is known. Zephyr versions >= 1.14.2, >= 2.4.0, >= 2.5.0 contain Use of Multiple Resources with Duplicate Identifier (CWE-694). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-j76f-35mc-4h63
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5cpe:2.3:o:zephyrproject:zephyr:1.14.2:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:o:zephyrproject:zephyr:1.14.2:*:*:*:*:*:*:*
- cpe:2.3:o:zephyrproject:zephyr:2.4.0:*:*:*:*:*:*:*
- cpe:2.3:o:zephyrproject:zephyr:2.5.0:*:*:*:*:*:*:*
- (no CPE)range: >=1.14.2, >=2.4.0, >=2.5.0
- (no CPE)range: 1.14.2
Patches
Vulnerability mechanics
References
1- github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-j76f-35mc-4h63nvdExploitPatchThird Party Advisory
News mentions
0No linked articles in our index yet.