← Back

CVE-2019-17060

nvd nist
Published: Feb 10, 2020Modified: Nov 21, 2024

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

The Bluetooth Low Energy (BLE) stack implementation on the NXP KW41Z (based on the MCUXpresso SDK with Bluetooth Low Energy Driver 2.2.1 and earlier) does not properly restrict the BLE Link Layer header and executes certain memory contents upon receiving a packet with a Link Layer ID (LLID) equal to zero. This allows attackers within radio range to cause deadlocks, cause anomalous behavior in the BLE state machine, or trigger a buffer overflow via a crafted BLE Link Layer frame.

Affected (1)

1 product
Configuration A
1 vulnerable · 8 platform
Vulnerable SoftwareAffected Versions
Up to 2.2.1
Running on/withPlatform Versions
Nxp
Kw31z
All versions
Nxp
Kw34
All versions
Nxp
Kw35
All versions
Nxp
Kw36
All versions
Nxp
Kw37
All versions
Nxp
Kw38
All versions
Nxp
Kw39
All versions
Nxp
Kw41z
All versions

References (4)

Source: cve@mitre.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.