PT-2019-13515 · Arduino · Arduino

Joe Loughry

·

Published

2019-07-19

·

Updated

2020-08-24

·

CVE-2019-13991

CVSS v3.1

6.5

Medium

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Arduino versions prior to Rev3
Description The issue allows remote attackers to send data to LEDs directly connected to GPIO pins via a laser, due to LED photosensitivity.
Recommendations For Arduino versions prior to Rev3, consider using alternative methods to control LEDs that are not susceptible to photosensitivity, or implement physical shielding to prevent external light sources from interfering with the LEDs.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2019-13991

Affected Products

Arduino