← Back

Ti

ti

28 CVEs • 59 products

Products (59)

Click to collapse
Toggle
Z Stack
z-stack
Ble Stack
ble-stack
15.4 Stack
15.4-stack
Ble5 Stack
ble5-stack
Easylink
easylink
Openthread
openthread
Cc2640
cc2640
Cc2650
cc2650
Cc2640r2f
cc2640r2f
Cc1350
cc1350
Tm4c123
tm4c123
Tm4c129
tm4c129
Cc256xc Bt Sp
cc256xc-bt-sp
Cc256xb Bt Sp
cc256xb-bt-sp
Wl18xx Bt Sp
wl18xx-bt-sp
Cc2640r2
cc2640r2
Cc2540/1
cc2540/1
Cc2538
cc2538
Cc256xcqfn Em
cc256xcqfn-em
Cc3120
cc3120
Cc3130
cc3130
Cc3135
cc3135
Cc3220r
cc3220r
Cc3220s
cc3220s
Cc3220sf
cc3220sf
Cc3230s
cc3230s
Cc3230sf
cc3230sf
Cc3235s
cc3235s
Cc3235sf
cc3235sf
Cc3100
cc3100
Cc3200
cc3200
Omap L138
omap_l138

CVEs (28)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ti
1Fusion Digital Power Designer
Nov 21, 2024
Sep 12, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
An issue in Texas Instruments Fusion Digital Power Designer v.7.10.1 allows a local attacker to obtain sensitive information via the plaintext storage of credentials
2Amazon
Ti
6Freertos
Simplelink Cc13xx Software Development KitSimplelink Cc26xx Software Development Kit+3 more
Nov 21, 2024
Nov 21, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Texas Instruments devices running FREERTOS, malloc returns a valid pointer to a small buffer on extremely large values, which can trigger an integer overflow vulnerability in 'malloc' for FreeRTOS, resulting in code e...Show more
Texas Instruments devices running FREERTOS, malloc returns a valid pointer to a small buffer on extremely large values, which can trigger an integer overflow vulnerability in 'malloc' for FreeRTOS, resulting in code execution.Show less
1Ti
6Real Time Operating System
Simplelink Cc13xx Software Development KitSimplelink Cc26xx Software Development Kit+3 more
Nov 21, 2024
Nov 21, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Texas Instruments TI-RTOS, when configured to use HeapMem heap(default), malloc returns a valid pointer to a small buffer on extremely large values, which can trigger an integer overflow vulnerability in 'HeapMem_allo...Show more
Texas Instruments TI-RTOS, when configured to use HeapMem heap(default), malloc returns a valid pointer to a small buffer on extremely large values, which can trigger an integer overflow vulnerability in 'HeapMem_allocUnprotected' and result in code execution.Show less
1Ti
6Real Time Operating System
Simplelink Cc13xx Software Development KitSimplelink Cc26xx Software Development Kit+3 more
Nov 21, 2024
Nov 20, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Texas Instruments TI-RTOS returns a valid pointer to a small buffer on extremely large values. This can trigger an integer overflow vulnerability in 'HeapTrack_alloc' and result in code execution.
1Ti
6Real Time Operating System
Simplelink Cc13xx Software Development KitSimplelink Cc26xx Software Development Kit+3 more
Nov 21, 2024
Nov 20, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Texas Instruments TI-RTOS, when configured to use HeapMem heap(default), malloc returns a valid pointer to a small buffer on extremely large values, which can trigger an integer overflow vulnerability in 'HeapMem_...Show more
Texas Instruments TI-RTOS, when configured to use HeapMem heap(default), malloc returns a valid pointer to a small buffer on extremely large values, which can trigger an integer overflow vulnerability in 'HeapMem_allocUnprotected' and result in code execution. Show less
1Ti
1Omap L138 Firmware
Nov 21, 2024
Oct 19, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
The Texas Instruments OMAP L138 (secure variants) trusted execution environment (TEE) lacks a bounds check on the signature size field in the SK_LOAD module loading routine, present in mask ROM. A module with a sufficien...Show more
The Texas Instruments OMAP L138 (secure variants) trusted execution environment (TEE) lacks a bounds check on the signature size field in the SK_LOAD module loading routine, present in mask ROM. A module with a sufficiently large signature field causes a stack overflow, affecting secure kernel data pages. This can be leveraged to obtain arbitrary code execution in secure supervisor context by overwriting a SHA256 function pointer in the secure kernel data area when loading a forged, unsigned SK_LOAD module encrypted with the CEK (obtainable through CVE-2022-25332). This constitutes a full break of the TEE security architecture.Show less
1Ti
1Omap L138 Firmware
Nov 21, 2024
Oct 19, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
The Texas Instruments OMAP L138 (secure variants) trusted execution environment (TEE) performs an RSA check implemented in mask ROM when loading a module through the SK_LOAD routine. However, only the module header authe...Show more
The Texas Instruments OMAP L138 (secure variants) trusted execution environment (TEE) performs an RSA check implemented in mask ROM when loading a module through the SK_LOAD routine. However, only the module header authenticity is validated. An adversary can re-use any correctly signed header and append a forged payload, to be encrypted using the CEK (obtainable through CVE-2022-25332) in order to obtain arbitrary code execution in secure context. This constitutes a full break of the TEE security architecture.Show less
1Ti
1Omap L138 Firmware
Nov 21, 2024
Oct 19, 2023
N/A· v4
4.1 MEDIUM· v3
N/A· v2
The AES implementation in the Texas Instruments OMAP L138 (secure variants), present in mask ROM, suffers from a timing side channel which can be exploited by an adversary with non-secure supervisor privileges by managin...Show more
The AES implementation in the Texas Instruments OMAP L138 (secure variants), present in mask ROM, suffers from a timing side channel which can be exploited by an adversary with non-secure supervisor privileges by managing cache contents and collecting timing information for different ciphertext inputs. Using this side channel, the SK_LOAD secure kernel routine can be used to recover the Customer Encryption Key (CEK).Show less
1Ti
1Wilink8 Wifi Mcp8
May 5, 2025
Aug 14, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The Texas Instruments (TI) WiLink WL18xx MCP driver does not limit the number of information elements (IEs) of type XCC_EXT_1_IE_ID or XCC_EXT_2_IE_ID that can be parsed in a management frame. Using a specially crafted f...Show more
The Texas Instruments (TI) WiLink WL18xx MCP driver does not limit the number of information elements (IEs) of type XCC_EXT_1_IE_ID or XCC_EXT_2_IE_ID that can be parsed in a management frame. Using a specially crafted frame, a buffer overflow can be triggered that can potentially lead to remote code execution. This affects WILINK8-WIFI-MCP8 version 8.5_SP3 and earlier.Show less
1Ti
3Cc3100 Firmware
Cc3200 FirmwareSimplelink Cc32xx Software Development Kit
Nov 21, 2024
Feb 16, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An information disclosure vulnerability exists in the HTTP Server /ping.html functionality of Texas Instruments CC3200 SimpleLink Solution NWP 2.9.0.0. A specially-crafted HTTP request can lead to an uninitialized read....Show more
An information disclosure vulnerability exists in the HTTP Server /ping.html functionality of Texas Instruments CC3200 SimpleLink Solution NWP 2.9.0.0. A specially-crafted HTTP request can lead to an uninitialized read. An attacker can send an HTTP request to trigger this vulnerability.Show less
1Ti
715.4 Stack
Ble5 StackDynamic Multi Protocal Manager+4 more
Nov 21, 2024
Sep 20, 2021
N/A· v4
6.8 MEDIUM· v3
4.3 MEDIUM· v2
TI’s BLE stack caches and reuses the LTK’s property for a bonded mobile. A LTK can be an unauthenticated-and-no-MITM-protection key created by Just Works or an authenticated-and-MITM-protection key created by Passkey Ent...Show more
TI’s BLE stack caches and reuses the LTK’s property for a bonded mobile. A LTK can be an unauthenticated-and-no-MITM-protection key created by Just Works or an authenticated-and-MITM-protection key created by Passkey Entry, Numeric Comparison or OOB. Assume that a victim mobile uses secure pairing to pair with a victim BLE device based on TI chips and generate an authenticated-and-MITM-protection LTK. If a fake mobile with the victim mobile’s MAC address uses Just Works and pairs with the victim device, the generated LTK still has the property of authenticated-and-MITM-protection. Therefore, the fake mobile can access attributes with the authenticated read/write permission.Show less
1Ti
1Cc256xcqfn Em Firmware
Nov 21, 2024
Sep 7, 2021
N/A· v4
6.5 MEDIUM· v3
3.3 LOW· v2
The Bluetooth Classic implementation on the Texas Instruments CC256XCQFN-EM does not properly handle the reception of continuous LMP_AU_Rand packets, allowing attackers in radio range to trigger a denial of service (dead...Show more
The Bluetooth Classic implementation on the Texas Instruments CC256XCQFN-EM does not properly handle the reception of continuous LMP_AU_Rand packets, allowing attackers in radio range to trigger a denial of service (deadlock) of the device by flooding it with LMP_AU_Rand packets after the paging procedure.Show less
1Ti
7Cc3100 Software Development Kit
Cc3200 Software Development KitSimplelink Cc13x0 Software Development Kit+4 more
Nov 21, 2024
May 7, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
An integer overflow exists in the APIs of the host MCU while trying to connect to a WIFI network may lead to issues such as a denial-of-service condition or code execution on the SimpleLink Wi-Fi (MSP432E4 SDK: v4.20.00....Show more
An integer overflow exists in the APIs of the host MCU while trying to connect to a WIFI network may lead to issues such as a denial-of-service condition or code execution on the SimpleLink Wi-Fi (MSP432E4 SDK: v4.20.00.12 and prior, CC32XX SDK v4.30.00.06 and prior, CC13X0 SDK versions prior to v4.10.03, CC13X2 and CC26XX SDK versions prior to v4.40.00, CC3200 SDK v1.5.0 and prior, CC3100 SDK v1.3.0 and prior).Show less
1Ti
7Cc3100 Software Development Kit
Cc3200 Software Development KitSimplelink Cc13x0 Software Development Kit+4 more
Nov 21, 2024
May 7, 2021
N/A· v4
8.0 HIGH· v3
6.0 MEDIUM· v2
The affected product is vulnerable to stack-based buffer overflow while processing over-the-air firmware updates from the CDN server, which may allow an attacker to remotely execute code on the SimpleLink Wi-Fi (MSP432E4...Show more
The affected product is vulnerable to stack-based buffer overflow while processing over-the-air firmware updates from the CDN server, which may allow an attacker to remotely execute code on the SimpleLink Wi-Fi (MSP432E4 SDK: v4.20.00.12 and prior, CC32XX SDK v4.30.00.06 and prior, CC13X0 SDK versions prior to v4.10.03, CC13X2 and CC26XX SDK versions prior to v4.40.00, CC3200 SDK v1.5.0 and prior, CC3100 SDK v1.3.0 and prior).Show less
1Ti
7Cc3100 Software Development Kit
Cc3200 Software Development KitSimplelink Cc13x0 Software Development Kit+4 more
Nov 21, 2024
May 7, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Multiple integer overflow issues exist while processing long domain names, which may allow an attacker to remotely execute code on the SimpleLink Wi-Fi (MSP432E4 SDK: v4.20.00.12 and prior, CC32XX SDK v4.30.00.06 and pri...Show more
Multiple integer overflow issues exist while processing long domain names, which may allow an attacker to remotely execute code on the SimpleLink Wi-Fi (MSP432E4 SDK: v4.20.00.12 and prior, CC32XX SDK v4.30.00.06 and prior, CC13X0 SDK versions prior to v4.10.03, CC13X2 and CC26XX SDK versions prior to v4.40.00, CC3200 SDK v1.5.0 and prior, CC3100 SDK v1.3.0 and prior).Show less
1Ti
7Cc3100 Software Development Kit
Cc3200 Software Development KitSimplelink Cc13x0 Software Development Kit+4 more
Nov 21, 2024
May 7, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The affected product is vulnerable to an integer overflow while processing HTTP headers, which may allow an attacker to remotely execute code on the SimpleLink Wi-Fi (MSP432E4 SDK: v4.20.00.12 and prior, CC32XX SDK v4.30...Show more
The affected product is vulnerable to an integer overflow while processing HTTP headers, which may allow an attacker to remotely execute code on the SimpleLink Wi-Fi (MSP432E4 SDK: v4.20.00.12 and prior, CC32XX SDK v4.30.00.06 and prior, CC13X0 SDK versions prior to v4.10.03, CC13X2 and CC26XX SDK versions prior to v4.40.00, CC3200 SDK v1.5.0 and prior, CC3100 SDK v1.3.0 and prior).Show less
1Ti
7Cc3100 Software Development Kit
Cc3200 Software Development KitSimplelink Cc13x0 Software Development Kit+4 more
Nov 21, 2024
May 7, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
The affected product is vulnerable to integer overflow while parsing malformed over-the-air firmware update files, which may allow an attacker to remotely execute code on SimpleLink Wi-Fi (MSP432E4 SDK: v4.20.00.12 and p...Show more
The affected product is vulnerable to integer overflow while parsing malformed over-the-air firmware update files, which may allow an attacker to remotely execute code on SimpleLink Wi-Fi (MSP432E4 SDK: v4.20.00.12 and prior, CC32XX SDK v4.30.00.06 and prior, CC13X0 SDK versions prior to v4.10.03, CC13X2 and CC26XX SDK versions prior to v4.40.00, CC3200 SDK v1.5.0 and prior, CC3100 SDK v1.3.0 and prior).Show less
1Ti
1Code Composer Studio Intgrated Development Environment
Nov 21, 2024
Jan 26, 2021
N/A· v4
5.3 MEDIUM· v3
4.3 MEDIUM· v2
jxbrowser in TI Code Composer Studio IDE 8.x through 10.x before 10.1.1 does not verify X.509 certificates for HTTPS.
1Ti
1Z Stack
Nov 21, 2024
Oct 27, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The Zigbee protocol implementation on Texas Instruments CC2538 devices with Z-Stack 3.0.1 does not properly process a ZCL Discover Commands Received Response message or a ZCL Discover Commands Generated Response message....Show more
The Zigbee protocol implementation on Texas Instruments CC2538 devices with Z-Stack 3.0.1 does not properly process a ZCL Discover Commands Received Response message or a ZCL Discover Commands Generated Response message. It crashes in zclParseInDiscCmdsRspCmd().Show less
1Ti
1Z Stack
Nov 21, 2024
Oct 27, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The Zigbee protocol implementation on Texas Instruments CC2538 devices with Z-Stack 3.0.1 does not properly process a ZCL Read Reporting Configuration Response message. It crashes in zclHandleExternal().