CVE-2022-2741 - CVE House
Back to Database
Status published High CVE-2022-2741

can: denial-of-service can be triggered by a crafted CAN frame

Vulnerability Description

The denial-of-service can be triggered by transmitting a carefully crafted CAN frame on the same CAN network as the vulnerable node. The frame must have a CAN ID matching an installed filter in the vulnerable node (this can easily be guessed based on CAN traffic analyses). The frame must contain the opposite RTR bit as what the filter installed in the vulnerable node contains (if the filter matches RTR frames, the frame must be a data frame or vice versa).

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-2741

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

zephyrproject-rtos

View all reports →

Affected Software

zephyr
Vulnerable Versions:
unspecified

Timeline

Official Publish: October 31st, 2022
Last Modified: May 5th, 2025
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H

Weaknesses (CWE)