CVE-2021-22679: Integer Overflow
The affected product is vulnerable to an integer overflow while processing HTTP headers, which may allow an attacker to remotely execute code on the SimpleLink Wi-Fi (MSP432E4 SDK: v4.20.00.12 and prior, CC32XX SDK v4.30.00.06 and prior, CC13X0 SDK versions prior to v4.10.03, CC13X2 and CC26XX SDK versions prior to v4.40.00, CC3200 SDK v1.5.0 and prior, CC3100 SDK v1.3.0 and prior).
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-22679?
CVE-2021-22679 is a vulnerability that allows an attacker to remotely execute code on the affected product due to an integer overflow in processing HTTP headers.
Which products are affected by CVE-2021-22679?
The SimpleLink Wi-Fi (MSP432E4 SDK: v4.20.00.12 and prior, CC32XX SDK v4.30.00.06 and prior, CC13X0 SDK versions prior to v4.10.03, CC13X2 and CC26XX SDK versions prior to v4.40.00) are affected by CVE-2021-22679.
What is the severity of CVE-2021-22679?
CVE-2021-22679 has a severity rating of 9.8 (Critical).
How can an attacker exploit CVE-2021-22679?
An attacker can exploit CVE-2021-22679 by sending malicious HTTP headers, triggering an integer overflow and potentially executing remote code.
Is there a fix available for CVE-2021-22679?
Yes, updating to the latest versions of the affected SDKs (SimpleLink Wi-Fi (MSP432E4 SDK v4.20.00.13 or later, CC32XX SDK v4.30.00.07 or later, CC13X0 SDK v4.10.03 or later, CC13X2 and CC26XX SDK v4.40.01 or later) will fix CVE-2021-22679.