CVE-2019-17520: Medium severity ti simplelink cc2640r2 software development kit vulnerability
The Bluetooth Low Energy implementation on Texas Instruments SDK through 3.30.00.20 for CC2640R2 devices does not properly restrict the SM Public Key packet on reception, allowing attackers in radio range to cause a denial of service (crash) via crafted packets.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2019-17520.
What is the severity level of CVE-2019-17520?
CVE-2019-17520 has a severity level of 6.5 (medium).
Which devices are affected by this vulnerability?
The Texas Instruments CC2640R2 devices with software development kit (SDK) version 3.30.00.20 are affected by this vulnerability.
How can an attacker exploit this vulnerability?
An attacker within radio range can exploit this vulnerability by sending crafted packets to cause a denial of service (crash) on the affected devices.
Are there any known fixes or patches available for this vulnerability?
At the moment, there is no known fix or patch available for this vulnerability. It is recommended to follow the guidance provided by Texas Instruments and stay updated on any official announcements or recommendations regarding this vulnerability.