VYPR

BLE-STACK

by Texas Instruments

CVEs (3)

  • CVE-2018-16986HigNov 6, 2018
    risk 0.57cvss 8.8epss 0.03

    Texas Instruments BLE-STACK v2.2.1 for SimpleLink CC2640 and CC2650 devices allows remote attackers to execute arbitrary code via a malformed packet that triggers a buffer overflow.

  • CVE-2020-16630MedSep 20, 2021
    risk 0.44cvss 6.8epss 0.01

    TI’s BLE stack caches and reuses the LTK’s property for a bonded mobile. A LTK can be an unauthenticated-and-no-MITM-protection key created by Just Works or an authenticated-and-MITM-protection key created by Passkey Entry, Numeric Comparison or OOB. Assume that a victim…

  • CVE-2019-19193MedFeb 10, 2020
    risk 0.42cvss 6.5epss 0.01

    The Bluetooth Low Energy peripheral implementation on Texas Instruments SIMPLELINK-CC2640R2-SDK through 3.30.00.20 and BLE-STACK through 1.5.0 before Q4 2019 for CC2640R2 and CC2540/1 devices does not properly restrict the advertisement connection request packet on reception,…