Bluetooth Low Energy Stack Vulnerability in Cypress PSoC 4 Devices
CVE-2019-17061
6.5MEDIUM
What is CVE-2019-17061?
The Bluetooth Low Energy (BLE) stack on Cypress PSoC 4 devices contains a vulnerability due to improper validation of the BLE Link Layer header. When a packet with a Link Layer ID (LLID) of zero is received, it allows for unexpected execution of memory contents. This can lead to various issues including deadlocks, erratic behavior in the BLE state machine, and potential buffer overflows when attackers exploit crafted BLE Link Layer frames within radio proximity.
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
