PT-2020-14482 · Silicon · Silicon Labs Bluetooth Low Energy Sdk

Published

2020-08-16

·

Updated

2020-08-24

·

CVE-2020-15531

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Silicon Labs Bluetooth Low Energy SDK versions prior to 2.13.3
Description The issue is related to a buffer overflow that can be triggered via packet data, leading to a remote code execution vulnerability in Bluetooth Low Energy (LE) for EFR32 SoCs and associated modules. This vulnerability affects devices running the Bluetooth SDK that support Central or Observer roles.
Recommendations For versions prior to 2.13.3, update to version 2.13.3 or later to resolve the issue. As a temporary workaround, consider restricting access to Bluetooth LE functionality to minimize the risk of exploitation.

Exploit

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-15531

Affected Products

Silicon Labs Bluetooth Low Energy Sdk