PT-2018-1870 · Aruba+1 · Aruba Access Point+1

Publicado

2018-07-09

·

Atualizado

2020-08-24

·

CVE-2018-7080

CVSS v2.0

7.9

Alta

VetorAV:A/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Texas Instruments Bluetooth Low Energy versions (affected versions not specified) Aruba Access points (affected versions not specified)
Description The issue is caused by a repeated memory release in the OAD mechanism of Texas Instruments Bluetooth Low Energy microcontroller firmware. An attacker could exploit this to gain full control over the device. For Aruba Access points, the vulnerability exists in the firmware of embedded BLE radios and could allow an attacker to install malicious firmware and gain access to the console port if the BLE radio is enabled.
Recommendations For Texas Instruments Bluetooth Low Energy, at the moment, there is no information about a newer version that contains a fix for this vulnerability. For Aruba Access points, consider disabling the BLE radio to minimize the risk of exploitation, as it is disabled by default.

Double Free

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2018-01472
CVE-2018-7080

Produtos afetados

Aruba Access Point
Texas Instruments Bluetooth Low Energy