CVE-2019-19193: Medium severity ti ble5-stack vulnerability
The Bluetooth Low Energy peripheral implementation on Texas Instruments SIMPLELINK-CC2640R2-SDK through 3.30.00.20 and BLE-STACK through 1.5.0 before Q4 2019 for CC2640R2 and CC2540/1 devices does not properly restrict the advertisement connection request packet on reception, allowing attackers in radio range to cause a denial of service (crash) via a crafted packet.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-19193?
CVE-2019-19193 is a vulnerability in the Bluetooth Low Energy peripheral implementation on Texas Instruments SIMPLELINK-CC2640R2-SDK and BLE-STACK, allowing attackers to bypass security restrictions.
What software is affected by CVE-2019-19193?
Texas Instruments SIMPLELINK-CC2640R2-SDK through version 3.30.00.20 and BLE-STACK through version 1.5.0 before Q4 2019 for CC2640R2 and CC2540/1 devices are affected.
What is the severity of CVE-2019-19193?
CVE-2019-19193 has a severity rating of 6.5, which is considered medium.
How can attackers exploit CVE-2019-19193?
Attackers can exploit CVE-2019-19193 by sending a malicious advertisement connection request packet, bypassing security restrictions.
Is there a fix for CVE-2019-19193?
To fix CVE-2019-19193, it is recommended to update the affected software to versions beyond the vulnerable ones mentioned.