OpenSynergy BlueSDK (aka Blue SDK) through 6.x has a Use-After-Free. The specific flaw exists within the BlueSDK Bluetooth stack. The issue results from the lack of validating the existence of an object before performing operations on the object (aka use after free). An attacker can leverage this to achieve remote code execution in the context of a user account under which the Bluetooth process runs.
Metrics
Affected Vendors & Products
References
History
Thu, 02 Oct 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:opensynergy:blue_sdk:*:*:*:*:*:*:*:* |
Mon, 15 Sep 2025 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Opensynergy
Opensynergy blue Sdk |
|
| Vendors & Products |
Opensynergy
Opensynergy blue Sdk |
Fri, 12 Sep 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-416 | |
| Metrics |
cvssV3_1
|
Fri, 12 Sep 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenSynergy BlueSDK (aka Blue SDK) through 6.x has a Use-After-Free. The specific flaw exists within the BlueSDK Bluetooth stack. The issue results from the lack of validating the existence of an object before performing operations on the object (aka use after free). An attacker can leverage this to achieve remote code execution in the context of a user account under which the Bluetooth process runs. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2025-09-12T00:00:00.000Z
Updated: 2025-09-12T17:31:13.731Z
Reserved: 2024-08-29T00:00:00.000Z
Link: CVE-2024-45434
Updated: 2025-09-12T17:30:15.386Z
Status : Analyzed
Published: 2025-09-12T17:15:46.950
Modified: 2025-10-02T20:00:43.860
Link: CVE-2024-45434
No data.