ZeroHour

CVE-2019-17519

PoC
CVSS 3.1
8.8 high
EPSS
1%p66
Published
()
Modified
Description

The Bluetooth Low Energy implementation on NXP SDK through 2.2.1 for KW41Z devices does not properly restrict the Link Layer payload length, allowing attackers in radio range to cause a buffer overflow via a crafted packet.

Vendors
nxp
Products
mcuxpresso software development kit
Weakness
CWE-120
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news