CVE-2026-14297
The Continuous Glucose Monitoring Service's Record Access Control Point (RACP) write handler `memcpy`s the entire attacker-supplied ATT write value into a fixed 20-byte BSS buffer.
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
A buffer overflow in the Bluetooth Continuous Glucose Monitoring Service (CGMS) Record Access Control Point (RACP) write handler allows an authenticated BLE peer to overflow a 20-byte static buffer into adjacent BSS memory. The exploitable impact cannot be predetermined - it is entirely dependent on the linker-assigned BSS layout of the specific firmware build, which may vary.
| CWE | CWE-787 |
| Vendor | nordic semiconductor asa |
| Product | nrf connect sdk |
| Published | Sep 7, 2026 |
| Last Updated | Sep 8, 2026 |
Stay Ahead of the Next One
Get instant alerts for nordic semiconductor asa nrf connect sdk
Be the first to know when new unknown vulnerabilities affecting nordic semiconductor asa nrf connect sdk are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Nordic Semiconductor ASA / nRF Connect SDK
2.2.0 โค 3.3.0
References
Credits
๐ https://github.com/V33RU