The Bluetooth Low Energy peripheral implementation on Texas Instruments SIMPLELINK-CC2640R2-SDK through 3.30.00.20 and BLE-STACK through 1.5.0 before Q4 2019 for CC2640R2 and CC2540/1 devices does not properly restrict the advertisement connection request packet on reception, allowing attackers in radio range to cause a denial of service (crash) via a crafted packet.
2020-02-10T21:51:32.843
2024-11-21T04:34:17.880
Modified
CVSSv3.1: 6.5 (MEDIUM)
AV:A/AC:L/Au:N/C:N/I:N/A:C
6.5
6.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | ti | ble-stack | ≤ 1.5.0 | Yes |
Application | ti | cc2640r2_software_development_kit | ≤ 3.30.00.20 | Yes |
Hardware | ti | cc2540\/1 | < q4_2019 | No |
Hardware | ti | cc2640r2 | < q4_2019 | No |