CVE-2021-21966
An information disclosure vulnerability exists in the HTTP Server /ping.html functionality of Texas Instruments CC3200 SimpleLink Solution NWP 2.9.0.0. A specially-crafted HTTP request can lead to an uninitialized read. An attacker can send an HTTP request to trigger this vulnerability.
Published:Feb 16, 2022
Last Modified:Nov 21, 2024
EPS:Feb 16, 2022
EPSS Score:0.02024
CVSS Score:5.3
Affected Products
Vendor
Product
Action
Vendor
Ti
Product
Cc3100
Ti
Cc3100
Vendor
Ti
Product
Cc3100 Firmware
Ti
Cc3100 Firmware
Vendor
Ti
Product
Cc3120
Ti
Cc3120
Vendor
Ti
Product
Cc3130
Ti
Cc3130
Vendor
Ti
Product
Cc3135
Ti
Cc3135
Vendor
Ti
Product
Cc3200
Ti
Cc3200
Vendor
Ti
Product
Cc3200 Firmware
Ti
Cc3200 Firmware
Vendor
Ti
Product
Cc3220r
Ti
Cc3220r
Vendor
Ti
Product
Cc3220s
Ti
Cc3220s
Vendor
Ti
Product
Cc3220sf
Ti
Cc3220sf
Vendor
Ti
Product
Cc3230s
Ti
Cc3230s
Vendor
Ti
Product
Cc3230sf
Ti
Cc3230sf
Vendor
Ti
Product
Cc3235s
Ti
Cc3235s
Vendor
Ti
Product
Cc3235sf
Ti
Cc3235sf
Vendor
Ti
Product
Simplelink Cc32xx Software Development Kit
Ti
Simplelink Cc32xx Software Development Kit
Exploits
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
No CAPEC recorded yet
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
