CVE-2019-17060
The Bluetooth Low Energy (BLE) stack implementation on the NXP KW41Z (based on the MCUXpresso SDK with Bluetooth Low Energy Driver 2.2.1 and earlier) does not properly restrict the BLE Link Layer header and executes certain memory contents upon receiving a packet with a Link Layer ID (LLID) equal to zero. This allows attackers within radio range to cause deadlocks, cause anomalous behavior in the BLE state machine, or trigger a buffer overflow via a crafted BLE Link Layer frame.
Published:Feb 10, 2020
Last Modified:Nov 21, 2024
EPS:Feb 10, 2020
EPSS Score:0.00504
CVSS Score:6.5
Affected Products
Vendor
Product
Action
Vendor
Nxp
Product
Kw31z
Nxp
Kw31z
Vendor
Nxp
Product
Kw34
Nxp
Kw34
Vendor
Nxp
Product
Kw35
Nxp
Kw35
Vendor
Nxp
Product
Kw36
Nxp
Kw36
Vendor
Nxp
Product
Kw37
Nxp
Kw37
Vendor
Nxp
Product
Kw38
Nxp
Kw38
Vendor
Nxp
Product
Kw39
Nxp
Kw39
Vendor
Nxp
Product
Kw41z
Nxp
Kw41z
Vendor
Nxp
Product
Mcuxpresso Software Development Kit
Nxp
Mcuxpresso Software Development Kit
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
