Zephyr JSON decoder incorrectly decodes array of array. Zephyr versions >= >1.14.0, >= >2.5.0 contain Attempt to Access Child of a Non-structure Pointer (CWE-588). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-289f-7mw3-2qf4
Threat-Mapped Scoring
Score: 0.0
Priority: Unclassified
EPSS
Score: 0.00334 Percentile:
0.55651
CVSS Scoring
CVSS v3.1 Score: 7.5
Severity: HIGH
Mapped CWE(s)
CWE-588
: Attempt to Access Child of a Non-structure Pointer