PT-2020-9913 · Texas Instruments · Texas Instruments Sdk
Published
2020-02-10
·
Updated
2020-02-14
·
CVE-2019-17520
CVSS v3.1
6.5
Medium
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Texas Instruments SDK versions through 3.30.00.20 for CC2640R2 devices
Description
The issue is related to the Bluetooth Low Energy implementation, which does not properly restrict the SM Public Key packet on reception. This allows attackers within radio range to cause a denial of service, resulting in a crash, by sending crafted packets.
Recommendations
For Texas Instruments SDK versions through 3.30.00.20, update to a version that properly restricts the SM Public Key packet on reception to prevent denial of service attacks.
Exploit
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Texas Instruments Sdk