PT-2021-15171 · Texas Instruments · Simplelink Wi-Fi
David Atch
+1
·
Published
2021-05-07
·
Updated
2021-05-17
·
CVE-2021-22677
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SimpleLink Wi-Fi versions prior to MSP432E4 SDK: v4.20.00.12
SimpleLink Wi-Fi versions prior to CC32XX SDK: v4.30.00.06
SimpleLink Wi-Fi versions prior to CC13X0 SDK: v4.10.03
SimpleLink Wi-Fi versions prior to CC13X2 and CC26XX SDK: v4.40.00
SimpleLink Wi-Fi versions prior to CC3200 SDK: v1.5.0
SimpleLink Wi-Fi versions prior to CC3100 SDK: v1.3.0
Description
An integer overflow exists in the APIs of the host MCU while trying to connect to a WIFI network, which may lead to issues such as a denial-of-service condition or code execution.
Recommendations
For versions prior to MSP432E4 SDK: v4.20.00.12, update to a version newer than v4.20.00.12.
For versions prior to CC32XX SDK: v4.30.00.06, update to a version newer than v4.30.00.06.
For versions prior to CC13X0 SDK: v4.10.03, update to a version newer than v4.10.03.
For versions prior to CC13X2 and CC26XX SDK: v4.40.00, update to a version newer than v4.40.00.
For versions prior to CC3200 SDK: v1.5.0, update to a version newer than v1.5.0.
For versions prior to CC3100 SDK: v1.3.0, update to a version newer than v1.3.0.
Fix
Integer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Simplelink Wi-Fi