CVE-2019-13991: Medium severity arduino firmware vulnerability
Embedded systems based on Arduino before Rev3 allow remote attackers to send data to LEDs (directly connected to GPIO pins) via a laser, because of LED photosensitivity.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-13991?
CVE-2019-13991 is a vulnerability in embedded systems based on Arduino before Rev3 that allows remote attackers to send data to LEDs via a laser due to LED photosensitivity.
How can this vulnerability be exploited?
This vulnerability can be exploited by remote attackers using a laser to send data to LEDs that are directly connected to GPIO pins in the Arduino system.
What is the severity rating of CVE-2019-13991?
The severity rating of CVE-2019-13991 is medium with a severity value of 6.5.
Which versions of Arduino firmware are affected by this vulnerability?
Embedded systems based on Arduino before Rev3 are affected by this vulnerability.
Is Arduino Arduino firmware Rev3 vulnerable to CVE-2019-13991?
Yes, Arduino firmware Rev3 is vulnerable to CVE-2019-13991.
Where can I find more information about CVE-2019-13991?
More information about CVE-2019-13991 can be found at the following reference: https://arxiv.org/abs/1907.00479