CVE-2019-17519
The Bluetooth Low Energy implementation on NXP SDK through 2.2.1 for KW41Z devices does not properly restrict the Link Layer payload length, allowing attackers in radio range to cause a buffer overflow via a crafted packet.
Published:Feb 12, 2020
Last Modified:Nov 21, 2024
EPS:Feb 12, 2020
EPSS Score:0.00081
CVSS Score:8.8
Affected Products
Vendor
Product
Action
Vendor
Nxp
Product
Kw31z
Nxp
Kw31z
Vendor
Nxp
Product
Kw34
Nxp
Kw34
Vendor
Nxp
Product
Kw35
Nxp
Kw35
Vendor
Nxp
Product
Kw36
Nxp
Kw36
Vendor
Nxp
Product
Kw37
Nxp
Kw37
Vendor
Nxp
Product
Kw38
Nxp
Kw38
Vendor
Nxp
Product
Kw39
Nxp
Kw39
Vendor
Nxp
Product
Kw41z
Nxp
Kw41z
Vendor
Nxp
Product
Mcuxpresso Software Development Kit
Nxp
Mcuxpresso Software Development Kit
Exploits
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
