CVE Feed

    Dashboard / CVE / CVE-2019-17519

    CVE-2019-17519

    The Bluetooth Low Energy implementation on NXP SDK through 2.2.1 for KW41Z devices does not properly restrict the Link Layer payload length, allowing attackers in radio range to cause a buffer overflow via a crafted packet.

    Published:Feb 12, 2020
    Last Modified:Nov 21, 2024
    EPS:Feb 12, 2020
    EPSS Score:0.00081
    CVSS Score:8.8

    Affected Products

    Vendor
    Nxp
    Product
    Kw31z
    Vendor
    Nxp
    Product
    Kw34
    Vendor
    Nxp
    Product
    Kw35
    Vendor
    Nxp
    Product
    Kw36
    Vendor
    Nxp
    Product
    Kw37
    Vendor
    Nxp
    Product
    Kw38
    Vendor
    Nxp
    Product
    Kw39
    Vendor
    Nxp
    Product
    Kw41z
    Vendor
    Nxp
    Product
    Mcuxpresso Software Development Kit

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High