PT-2022-8316 · Cypress · Cypress Wireless Combo

Francesco Gringoli

+1

·

Published

2022-02-15

·

Updated

2024-11-13

·

CVE-2020-10370

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cypress (and Broadcom) Wireless Combo chips versions prior to the 2021-01-26 Bluetooth firmware update
Description The issue allows a Bluetooth outage via a "Spectra" attack when a specific Bluetooth firmware update is not present. It is also related to Sweyntooth issues in the Bluetooth firmware.
Recommendations For versions prior to the 2021-01-26 Bluetooth firmware update, apply the 2021-01-26 Bluetooth firmware update to mitigate the risk of a Bluetooth outage via a "Spectra" attack.

Fix

Related Identifiers

CVE-2020-10370
OPENSUSE-SU-2024:11689-1

Affected Products

Cypress Wireless Combo