PT-2020-9913 · Texas Instruments · Texas Instruments Sdk

Published

2020-02-10

·

Updated

2020-02-14

·

CVE-2019-17520

CVSS v3.1

6.5

Medium

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Texas Instruments SDK versions through 3.30.00.20 for CC2640R2 devices
Description The issue is related to the Bluetooth Low Energy implementation, which does not properly restrict the SM Public Key packet on reception. This allows attackers within radio range to cause a denial of service, resulting in a crash, by sending crafted packets.
Recommendations For Texas Instruments SDK versions through 3.30.00.20, update to a version that properly restricts the SM Public Key packet on reception to prevent denial of service attacks.

Exploit

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-17520

Affected Products

Texas Instruments Sdk