PT-2021-15169 · Texas Instruments · Cc13X0 Sdk+7
David Atch
+1
·
Published
2021-05-07
·
Updated
2021-05-17
·
CVE-2021-22675
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Texas Instruments SimpleLink Wi-Fi versions prior to MSP432E4 SDK: v4.20.00.12
Texas Instruments SimpleLink Wi-Fi CC32XX SDK versions prior to v4.30.00.06
Texas Instruments SimpleLink Wi-Fi CC13X0 SDK versions prior to v4.10.03
Texas Instruments SimpleLink Wi-Fi CC13X2 and CC26XX SDK versions prior to v4.40.00
Texas Instruments SimpleLink Wi-Fi CC3200 SDK versions prior to v1.5.0
Texas Instruments SimpleLink Wi-Fi CC3100 SDK versions prior to v1.3.0
Description
The issue arises from an integer overflow when parsing malformed over-the-air firmware update files, potentially allowing remote code execution.
Recommendations
For MSP432E4 SDK versions prior to v4.20.00.12, update to a version later than v4.20.00.12 to resolve the issue.
For CC32XX SDK versions prior to v4.30.00.06, update to a version later than v4.30.00.06 to resolve the issue.
For CC13X0 SDK versions prior to v4.10.03, update to a version later than v4.10.03 to resolve the issue.
For CC13X2 and CC26XX SDK versions prior to v4.40.00, update to a version later than v4.40.00 to resolve the issue.
For CC3200 SDK versions prior to v1.5.0, update to a version later than v1.5.0 to resolve the issue.
For CC3100 SDK versions prior to v1.3.0, update to a version later than v1.3.0 to resolve the issue.
Fix
Integer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cc13X0 Sdk
Cc13X2 Sdk
Cc26Xx Sdk
Cc3100 Sdk
Cc3200 Sdk
Cc32Xx Sdk
Msp432E4 Sdk
Simplelink Wi-Fi