CVE-2019-15948
Texas Instruments CC256x and WL18xx dual-mode Bluetooth controller devices, when LE scan mode is used, allow remote attackers to trigger a buffer overflow via a malformed Bluetooth Low Energy advertising packet, to cause a denial of service or potentially execute arbitrary code. This affects CC256xC-BT-SP 1.2, CC256xB-BT-SP 1.8, and WL18xx-BT-SP 4.4.
Published:Nov 13, 2019
Last Modified:Nov 21, 2024
EPS:Nov 13, 2019
EPSS Score:0.08374
CVSS Score:8.8
Affected Products
Vendor
Product
Action
Vendor
Ti
Product
Cc256xb-bt-sp
Ti
Cc256xb-bt-sp
Vendor
Ti
Product
Cc256xb-bt-sp Firmware
Ti
Cc256xb-bt-sp Firmware
Vendor
Ti
Product
Cc256xc-bt-sp
Ti
Cc256xc-bt-sp
Vendor
Ti
Product
Cc256xc-bt-sp Firmware
Ti
Cc256xc-bt-sp Firmware
Vendor
Ti
Product
Wl18xx-bt-sp
Ti
Wl18xx-bt-sp
Vendor
Ti
Product
Wl18xx-bt-sp Firmware
Ti
Wl18xx-bt-sp Firmware
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
