Bluetooth Low Energy Vulnerability in Cypress PSoC 4 BLE Component
CVE-2019-16336

6.5MEDIUM

Key Information:

Vendor

Cypress

Vendor
CVE Published:
12 February 2020

What is CVE-2019-16336?

The Bluetooth Low Energy implementation in earlier versions of the Cypress PSoC 4 BLE component is susceptible to a denial of service attack. By exploiting this vulnerability, an attacker within radio range can send crafted BLE Link Layer frames that exceed the configured maximum RX payload size. This malformed data can cause the device to crash, interrupting normal service. It is recommended to upgrade to later versions of the component to mitigate this issue.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2019-16336 : Bluetooth Low Energy Vulnerability in Cypress PSoC 4 BLE Component