theheraldproject / herald-for-cpp

Herald for C++ - Reliable mobile Bluetooth communications - Native library & test apps
https://heraldprox.io
Other
13 stars 10 forks source link

Security Report: Pre-release validation of Bluetooth MESH CVEs #114

Open adamfowleruk opened 2 years ago

adamfowleruk commented 2 years ago

Investigate the following historic CVEs before releasing the first production (non Beta) version of Herald Bluetooth MESH beacon applications.

Sources:-

CVEs:-

BLOCKED Until #113 and #82 are completed. (As we can't close this issue off until the functionality is fully implemented as there may be more CVEs in the meantime).

adamfowleruk commented 2 years ago

Also for reference, past Zephyr RTOS vulnerabilities (MESH issues highlighted)

[4] Zephyr Vulnerabilities list - https://docs.zephyrproject.org/latest/security/vulnerabilities.html?highlight=mesh [5] MITRE website - https://cve.mitre.org

CVEs:-

adamfowleruk commented 2 years ago

Info from Nordic Semiconductor on NFC for OOB MESH provisioning:-