PT-2021-15171 · Texas Instruments · Simplelink Wi-Fi

David Atch

+1

·

Published

2021-05-07

·

Updated

2021-05-17

·

CVE-2021-22677

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SimpleLink Wi-Fi versions prior to MSP432E4 SDK: v4.20.00.12 SimpleLink Wi-Fi versions prior to CC32XX SDK: v4.30.00.06 SimpleLink Wi-Fi versions prior to CC13X0 SDK: v4.10.03 SimpleLink Wi-Fi versions prior to CC13X2 and CC26XX SDK: v4.40.00 SimpleLink Wi-Fi versions prior to CC3200 SDK: v1.5.0 SimpleLink Wi-Fi versions prior to CC3100 SDK: v1.3.0
Description An integer overflow exists in the APIs of the host MCU while trying to connect to a WIFI network, which may lead to issues such as a denial-of-service condition or code execution.
Recommendations For versions prior to MSP432E4 SDK: v4.20.00.12, update to a version newer than v4.20.00.12. For versions prior to CC32XX SDK: v4.30.00.06, update to a version newer than v4.30.00.06. For versions prior to CC13X0 SDK: v4.10.03, update to a version newer than v4.10.03. For versions prior to CC13X2 and CC26XX SDK: v4.40.00, update to a version newer than v4.40.00. For versions prior to CC3200 SDK: v1.5.0, update to a version newer than v1.5.0. For versions prior to CC3100 SDK: v1.3.0, update to a version newer than v1.3.0.

Fix

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-22677

Affected Products

Simplelink Wi-Fi