Monitoring Service (CGMS) Record Access Control Point (RACP) write handler
allows an authenticated BLE peer to overflow a 20-byte static buffer into
adjacent BSS memory. The exploitable impact cannot be predetermined - it
is entirely dependent on the linker-assigned BSS layout of the specific
firmware build, which may vary.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 08 Sep 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nordic Semiconductor Asa
Nordic Semiconductor Asa nrf Connect Sdk |
|
| Vendors & Products |
Nordic Semiconductor Asa
Nordic Semiconductor Asa nrf Connect Sdk |
Tue, 08 Sep 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 07 Sep 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A buffer overflow in the Bluetooth Continuous Glucose Monitoring Service (CGMS) Record Access Control Point (RACP) write handler allows an authenticated BLE peer to overflow a 20-byte static buffer into adjacent BSS memory. The exploitable impact cannot be predetermined - it is entirely dependent on the linker-assigned BSS layout of the specific firmware build, which may vary. | |
| Title | The Continuous Glucose Monitoring Service's Record Access Control Point (RACP) write handler `memcpy`s the entire attacker-supplied ATT write value into a fixed 20-byte BSS buffer. | |
| Weaknesses | CWE-787 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: YesWeHack
Published:
Updated: 2026-09-08T15:01:09.643Z
Reserved: 2026-07-01T09:51:25.497Z
Link: CVE-2026-14297
Updated: 2026-09-08T15:01:06.296Z
Status : Received
Published: 2026-09-07T09:17:15.430
Modified: 2026-09-08T15:18:42.070
Link: CVE-2026-14297
No data.
OpenCVE Enrichment
Updated: 2026-09-08T20:38:10Z
-
CWE-787
Out-of-bounds Write