CVE-2024-45434 Details
Description
OpenSynergy BlueSDK (aka Blue SDK) through 6.x has a Use-After-Free. The specific flaw exists within the BlueSDK Bluetooth stack. The issue results from the lack of validating the existence of an object before performing operations on the object (aka use after free). An attacker can leverage this to achieve remote code execution in the context of a user account under which the Bluetooth process runs.
A use-after-free vulnerability has been identified in the OpenSynergy BlueSDK Bluetooth stack, affecting versions through 6.x. This vulnerability arises from the Bluetooth stack's failure to validate the existence of an object before performing operations on it. An attacker can exploit this flaw to achieve remote code execution, executing arbitrary code in the context of the user account under which the Bluetooth process operates.
OpenSynergy has released patches for this vulnerability, which are available to customers. However, not all automotive manufacturers have applied the patch yet.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Sep 12, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://pcacybersecurity.com/resources/advisory/perfekt-blue | CISA-ADP | ExploitThird Party Advisory |
| https://pcacybersecurity.com/resources/advisory/perfekt-blue | [email protected] | ExploitThird Party Advisory |
| https://www.opensynergy.com/ | [email protected] | Product |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-416 | Use After Free | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| opensynergy blue sdk | <= 6.0.1 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 2, 2025 | Initial Analysis | [email protected] |
| Sep 12, 2025 | CVE Modified | CISA-ADP |
| Sep 12, 2025 | New CVE Received | [email protected] |