PT-2019-13515 · Arduino · Arduino
Joe Loughry
·
Published
2019-07-19
·
Updated
2020-08-24
·
CVE-2019-13991
CVSS v3.1
6.5
Medium
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Arduino versions prior to Rev3
Description
The issue allows remote attackers to send data to LEDs directly connected to GPIO pins via a laser, due to LED photosensitivity.
Recommendations
For Arduino versions prior to Rev3, consider using alternative methods to control LEDs that are not susceptible to photosensitivity, or implement physical shielding to prevent external light sources from interfering with the LEDs.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Arduino