First published: Tue Nov 06 2018(Updated: )
Texas Instruments BLE-STACK v2.2.1 for SimpleLink CC2640 and CC2650 devices allows remote attackers to execute arbitrary code via a malformed packet that triggers a buffer overflow.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ti Ble-stack | <=2.2.1 | |
Ti Cc2640 | ||
Ti Cc2650 | ||
Ti Ble-stack | =3.0.0 | |
Ti Cc2640r2f | ||
Ti Ble-stack | <=2.3.3 | |
Ti Cc1350 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-16986 is a vulnerability in Texas Instruments BLE-STACK v2.2.1 for SimpleLink CC2640 and CC2650 devices that allows remote attackers to execute arbitrary code via a malformed packet triggering a buffer overflow.
CVE-2018-16986 has a severity rating of 8.8 (high).
CVE-2018-16986 affects Texas Instruments BLE-STACK v2.2.1 and earlier versions.
CVE-2018-16986 falls into the CWE categories 119 (Improper Restriction of Operations within the Bounds of a Memory Buffer) and 787 (Out-of-bounds Write).
No, Texas Instruments CC2640 and CC2650 devices are not vulnerable to CVE-2018-16986.