CVE-2019-17060
6.5
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 2.8 / Impact: 3.6
Source: NVD
Description
The Bluetooth Low Energy (BLE) stack implementation on the NXP KW41Z (based on the MCUXpresso SDK with Bluetooth Low Energy Driver 2.2.1 and earlier) does not properly restrict the BLE Link Layer header and executes certain memory contents upon receiving a packet with a Link Layer ID (LLID) equal to zero. This allows attackers within radio range to cause deadlocks, cause anomalous behavior in the BLE state machine, or trigger a buffer overflow via a crafted BLE Link Layer frame.
Affected (1)
Products: Nxp: Mcuxpresso Software Development Kit
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.2.1 |
| Running on/with | Platform Versions |
|---|---|
Nxp Kw31z | All versions |
Nxp Kw34 | All versions |
Nxp Kw35 | All versions |
Nxp Kw36 | All versions |
Nxp Kw37 | All versions |
Nxp Kw38 | All versions |
Nxp Kw39 | All versions |
Nxp Kw41z | All versions |
References (4)
Source: cve@mitre.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.