CVE-2019-17061
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The Bluetooth Low Energy (BLE) stack implementation on Cypress PSoC 4 through 3.62 devices does not properly restrict the BLE Link Layer header and executes certain memory contents upon receiving a packet with a Link Layer ID (LLID) equal to zero. This allows attackers within radio range to cause deadlocks, cause anomalous behavior in the BLE state machine, or trigger a buffer overflow via a crafted BLE Link Layer frame.
La implementación de la pila de Bluetooth Low Energy (BLE) en dispositivos Cypress PSoC 4 versiones hasta 3.62, no restringe apropiadamente el encabezado BLE Link Layer y ejecuta determinados contenidos de memoria tras recibir un paquete con un Link Layer ID (LLID) igual a cero. Esto permite a atacantes dentro del radio de alcance causar puntos muertos, causar un comportamiento anómalo en la máquina de estado BLE o desencadenar un desbordamiento del búfer por medio de una trama BLE Link Layer diseñada.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-10-01 CVE Reserved
- 2020-02-10 CVE Published
- 2023-12-15 EPSS Updated
- 2024-08-05 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://asset-group.github.io/disclosures/sweyntooth | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://community.cypress.com/thread/53680 | 2022-01-01 | |
https://www.cypress.com/products/ble-bluetooth | 2022-01-01 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cypress Search vendor "Cypress" | Psoc 4 Ble Search vendor "Cypress" for product "Psoc 4 Ble" | <= 3.62 Search vendor "Cypress" for product "Psoc 4 Ble" and version " <= 3.62" | - |
Affected
| in | Cypress Search vendor "Cypress" | Psoc 4 Search vendor "Cypress" for product "Psoc 4" | - | - |
Safe
|