CVE-2019-17519: Buffer Overflow
Published Feb 12, 2020
·Updated
The Bluetooth Low Energy implementation on NXP SDK through 2.2.1 for KW41Z devices does not properly restrict the Link Layer payload length, allowing attackers in radio range to cause a buffer overflow via a crafted packet.
Affected Software
9 affected components
NXP Mcuxpresso Software Development Kit<=2.2.1
NXP Kw31z
NXP Kw34
NXP Kw35
NXP Kw36
NXP Kw37
NXP Kw38
NXP Kw39
NXP KW41Z
Event History
Feb 12, 2020
CVE Published
via MITRE·06:04 PM
Data Sourced
via MITRE·06:04 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2019-17519.
2
What is the severity of CVE-2019-17519?
The severity of CVE-2019-17519 is high (8.8).
3
Which software is affected by CVE-2019-17519?
NXP SDK through 2.2.1 for KW41Z devices is affected by CVE-2019-17519.
4
How can an attacker exploit CVE-2019-17519?
An attacker in radio range can cause a buffer overflow by sending a crafted packet that exceeds the Link Layer payload length.
5
Is NXP KW41Z vulnerable to CVE-2019-17519?
No, NXP KW41Z is not vulnerable to CVE-2019-17519.