Page 2 of 32 results (0.007 seconds)

CVSS: 5.3EPSS: 2%CPEs: 15EXPL: 1

16 Feb 2022 — An information disclosure vulnerability exists in the HTTP Server /ping.html functionality of Texas Instruments CC3200 SimpleLink Solution NWP 2.9.0.0. A specially-crafted HTTP request can lead to an uninitialized read. An attacker can send an HTTP request to trigger this vulnerability. Se presenta una vulnerabilidad de divulgación de información en la funcionalidad HTTP Server /ping.html de Texas Instruments CC3200 SimpleLink Solution NWP versión 2.9.0.0. Una petición HTTP especialmente diseñada puede conl... • https://talosintelligence.com/vulnerability_reports/TALOS-2021-1393 • CWE-457: Use of Uninitialized Variable CWE-908: Use of Uninitialized Resource •

CVSS: 6.8EPSS: 0%CPEs: 7EXPL: 1

20 Sep 2021 — TI’s BLE stack caches and reuses the LTK’s property for a bonded mobile. A LTK can be an unauthenticated-and-no-MITM-protection key created by Just Works or an authenticated-and-MITM-protection key created by Passkey Entry, Numeric Comparison or OOB. Assume that a victim mobile uses secure pairing to pair with a victim BLE device based on TI chips and generate an authenticated-and-MITM-protection LTK. If a fake mobile with the victim mobile’s MAC address uses Just Works and pairs with the victim device, the... • http://software-dl.ti.com/simplelink/esd/simplelink_cc13x2_26x2_sdk/3.20.00.68/exports/changelog.html • CWE-863: Incorrect Authorization •

CVSS: 6.5EPSS: 0%CPEs: 2EXPL: 0

03 Sep 2021 — The Bluetooth Classic implementation on the Texas Instruments CC256XCQFN-EM does not properly handle the reception of continuous LMP_AU_Rand packets, allowing attackers in radio range to trigger a denial of service (deadlock) of the device by flooding it with LMP_AU_Rand packets after the paging procedure. Una implementación de Bluetooth Classic en el Texas Instruments CC256XCQFN-EM, no maneja apropiadamente la recepción de paquetes LMP_AU_Rand continuos, permitiendo a atacantes en el rango de radio desenca... • https://dl.packetstormsecurity.net/papers/general/braktooth.pdf •

CVSS: 7.8EPSS: 0%CPEs: 7EXPL: 0

07 May 2021 — An integer overflow exists in the APIs of the host MCU while trying to connect to a WIFI network may lead to issues such as a denial-of-service condition or code execution on the SimpleLink Wi-Fi (MSP432E4 SDK: v4.20.00.12 and prior, CC32XX SDK v4.30.00.06 and prior, CC13X0 SDK versions prior to v4.10.03, CC13X2 and CC26XX SDK versions prior to v4.40.00, CC3200 SDK v1.5.0 and prior, CC3100 SDK v1.3.0 and prior). Se presenta un desbordamiento de enteros en la API del host MCU al intentar conectarse a una red... • https://us-cert.cisa.gov/ics/advisories/icsa-21-119-01 • CWE-190: Integer Overflow or Wraparound •

CVSS: 8.0EPSS: 0%CPEs: 7EXPL: 0

07 May 2021 — The affected product is vulnerable to stack-based buffer overflow while processing over-the-air firmware updates from the CDN server, which may allow an attacker to remotely execute code on the SimpleLink Wi-Fi (MSP432E4 SDK: v4.20.00.12 and prior, CC32XX SDK v4.30.00.06 and prior, CC13X0 SDK versions prior to v4.10.03, CC13X2 and CC26XX SDK versions prior to v4.40.00, CC3200 SDK v1.5.0 and prior, CC3100 SDK v1.3.0 and prior). El producto afectado es vulnerable a un desbordamiento del búfer en la región sta... • https://us-cert.cisa.gov/ics/advisories/icsa-21-119-01 • CWE-121: Stack-based Buffer Overflow CWE-787: Out-of-bounds Write •

CVSS: 9.8EPSS: 0%CPEs: 7EXPL: 0

07 May 2021 — Multiple integer overflow issues exist while processing long domain names, which may allow an attacker to remotely execute code on the SimpleLink Wi-Fi (MSP432E4 SDK: v4.20.00.12 and prior, CC32XX SDK v4.30.00.06 and prior, CC13X0 SDK versions prior to v4.10.03, CC13X2 and CC26XX SDK versions prior to v4.40.00, CC3200 SDK v1.5.0 and prior, CC3100 SDK v1.3.0 and prior). Se presentan varios problemas de desbordamiento de enteros al procesar nombres de dominio largos, lo que puede permitir a un atacante ejecut... • https://us-cert.cisa.gov/ics/advisories/icsa-21-119-01 • CWE-190: Integer Overflow or Wraparound •

CVSS: 9.8EPSS: 0%CPEs: 7EXPL: 0

07 May 2021 — The affected product is vulnerable to an integer overflow while processing HTTP headers, which may allow an attacker to remotely execute code on the SimpleLink Wi-Fi (MSP432E4 SDK: v4.20.00.12 and prior, CC32XX SDK v4.30.00.06 and prior, CC13X0 SDK versions prior to v4.10.03, CC13X2 and CC26XX SDK versions prior to v4.40.00, CC3200 SDK v1.5.0 and prior, CC3100 SDK v1.3.0 and prior). El producto afectado es vulnerable a un desbordamiento de enteros mientras procesa los encabezados HTTP, lo que puede permitir... • https://us-cert.cisa.gov/ics/advisories/icsa-21-119-01 • CWE-190: Integer Overflow or Wraparound •

CVSS: 7.2EPSS: 0%CPEs: 7EXPL: 0

07 May 2021 — The affected product is vulnerable to integer overflow while parsing malformed over-the-air firmware update files, which may allow an attacker to remotely execute code on SimpleLink Wi-Fi (MSP432E4 SDK: v4.20.00.12 and prior, CC32XX SDK v4.30.00.06 and prior, CC13X0 SDK versions prior to v4.10.03, CC13X2 and CC26XX SDK versions prior to v4.40.00, CC3200 SDK v1.5.0 and prior, CC3100 SDK v1.3.0 and prior). El producto afectado es vulnerable a un desbordamiento de enteros al analizar archivos de actualización ... • https://us-cert.cisa.gov/ics/advisories/icsa-21-119-01 • CWE-190: Integer Overflow or Wraparound •

CVSS: 5.3EPSS: 8%CPEs: 1EXPL: 0

23 Jan 2021 — jxbrowser in TI Code Composer Studio IDE 8.x through 10.x before 10.1.1 does not verify X.509 certificates for HTTPS. jxbrowser en TI Code Composer Studio IDE versiones 8.x hasta versiones 10.x anteriores a 10.1.1, no comprueba los certificados X.509 para HTTPS • https://sir.ext.ti.com/jira/browse/EXT_EP-10212 • CWE-295: Improper Certificate Validation •

CVSS: 8.2EPSS: 0%CPEs: 2EXPL: 0

27 Oct 2020 — The Zigbee protocol implementation on Texas Instruments CC2538 devices with Z-Stack 3.0.1 does not properly process a ZCL Write Attributes No Response message. It crashes in zclParseInWriteCmd() and does not update the specific attribute's value. La implementación del protocolo Zigbee en dispositivos CC2538 de Texas Instruments con Z-Stack versión 3.0.1, no procesa apropiadamente un mensaje ZCL Write Attributes No Response. Se bloquea en la función zclParseInWriteCmd() y no actualiza el valor del atrib... • https://github.com/zigbeeprotocol/Z-Fuzzer/tree/master/vulnerabilities •