CVE-2019-17061
The Bluetooth Low Energy (BLE) stack implementation on Cypress PSoC 4 through 3.62 devices does not properly restrict the BLE Link Layer header and executes certain memory contents upon receiving a packet with a Link Layer ID (LLID) equal to zero. This allows attackers within radio range to cause deadlocks, cause anomalous behavior in the BLE state machine, or trigger a buffer overflow via a crafted BLE Link Layer frame.
Published:Feb 10, 2020
Last Modified:Nov 21, 2024
EPS:Feb 10, 2020
EPSS Score:0.00699
CVSS Score:6.5
Affected Products
Vendor
Product
Action
Vendor
Cypress
Product
Psoc 4
Cypress
Psoc 4
Vendor
Cypress
Product
Psoc 4 Ble
Cypress
Psoc 4 Ble
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
