ZeroHour

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2019-16336
The Bluetooth Low Energy implementation in Cypress PSoC 4 BLE component 3.61 and earlier processes data channel frames with a payload length larger than the con

The Bluetooth Low Energy implementation in Cypress PSoC 4 BLE component 3.61 and earlier processes data channel frames with a payload length larger than the configured link layer maximum RX payload size, which allows attackers (in radio range) to cause a denial of service (crash) via a crafted BLE Link Layer frame.

NVD description · AI analysis pending
6.51% PoC ×2
  • cypress cyble-416045
  • cypress cybl11573
CVE-2019-17060
The Bluetooth Low Energy (BLE) stack implementation on the NXP KW41Z (based on the MCUXpresso SDK with Bluetooth Low Energy Driver 2.2.1 and earlier) does not p

The Bluetooth Low Energy (BLE) stack implementation on the NXP KW41Z (based on the MCUXpresso SDK with Bluetooth Low Energy Driver 2.2.1 and earlier) does not properly restrict the BLE Link Layer header and executes certain memory contents upon receiving a packet with a Link Layer ID (LLID) equal to zero. This allows attackers within radio range to cause deadlocks, cause anomalous behavior in the BLE state machine, or trigger a buffer overflow via a crafted BLE Link Layer frame.

NVD description · AI analysis pending
6.5<1%
  • nxp mcuxpresso software development kit
CVE-2019-17061
The Bluetooth Low Energy (BLE) stack implementation on Cypress PSoC 4 through 3.62 devices does not properly restrict the BLE Link Layer header and executes cer

The Bluetooth Low Energy (BLE) stack implementation on Cypress PSoC 4 through 3.62 devices does not properly restrict the BLE Link Layer header and executes certain memory contents upon receiving a packet with a Link Layer ID (LLID) equal to zero. This allows attackers within radio range to cause deadlocks, cause anomalous behavior in the BLE state machine, or trigger a buffer overflow via a crafted BLE Link Layer frame.

NVD description · AI analysis pending
6.5<1%
  • cypress psoc 4 ble
CVE-2019-17518
+1 in the same advisory: …17517
The Bluetooth Low Energy implementation on Dialog Semiconductor SDK through 1.0.14.1081 for DA1468x devices responds to link layer packets with a payload length

The Bluetooth Low Energy implementation on Dialog Semiconductor SDK through 1.0.14.1081 for DA1468x devices responds to link layer packets with a payload length larger than expected, allowing attackers in radio range to cause a buffer overflow via a crafted packet. This affects, for example, August Smart Lock.

NVD description · AI analysis pending
6.5
group max
<1%
  • dialog-semiconductor software development kit
CVE-2019-17519
The Bluetooth Low Energy implementation on NXP SDK through 2.2.1 for KW41Z devices does not properly restrict the Link Layer payload length, allowing attackers

The Bluetooth Low Energy implementation on NXP SDK through 2.2.1 for KW41Z devices does not properly restrict the Link Layer payload length, allowing attackers in radio range to cause a buffer overflow via a crafted packet.

NVD description · AI analysis pending
8.81% PoC
  • nxp mcuxpresso software development kit
CVE-2019-17520
The Bluetooth Low Energy implementation on Texas Instruments SDK through 3.30.00.20 for CC2640R2 devices does not properly restrict the SM Public Key packet on

The Bluetooth Low Energy implementation on Texas Instruments SDK through 3.30.00.20 for CC2640R2 devices does not properly restrict the SM Public Key packet on reception, allowing attackers in radio range to cause a denial of service (crash) via crafted packets.

NVD description · AI analysis pending
6.52% PoC
  • ti cc2640r2 software development kit
CVE-2019-19192
The Bluetooth Low Energy implementation on STMicroelectronics BLE Stack through 1.3.1 for STM32WB5x devices does not properly handle consecutive Attribute Proto

The Bluetooth Low Energy implementation on STMicroelectronics BLE Stack through 1.3.1 for STM32WB5x devices does not properly handle consecutive Attribute Protocol (ATT) requests on reception, allowing attackers in radio range to cause an event deadlock or crash via crafted packets.

NVD description · AI analysis pending
6.51% PoC
  • st wb55
  • st bluenrg-2
CVE-2019-19194
+1 in the same advisory: …19196
The Bluetooth Low Energy Secure Manager Protocol (SMP) implementation on Telink Semiconductor BLE SDK versions before November 2019 for TLSR8x5x through 3.4.0,

The Bluetooth Low Energy Secure Manager Protocol (SMP) implementation on Telink Semiconductor BLE SDK versions before November 2019 for TLSR8x5x through 3.4.0, TLSR823x through 1.3.0, and TLSR826x through 3.3 devices installs a zero long term key (LTK) if an out-of-order link-layer encryption request is received during Secure Connections pairing. An attacker in radio range can have arbitrary read/write access to protected GATT service data, cause a device crash, or possibly control a device's function by establishing an encrypted session with the zero LTK.

NVD description · AI analysis pending
8.8
group max
1% PoC
  • telink-semi tlsr8258 ble sdk
  • telink-semi tlsr8269 ble sdk
  • telink-semi tlsr8253 ble sdk
  • +1 more
CVE-2019-19195
The Bluetooth Low Energy implementation on Microchip Technology BluSDK Smart through 6.2 for ATSAMB11 devices does not properly restrict link-layer data length

The Bluetooth Low Energy implementation on Microchip Technology BluSDK Smart through 6.2 for ATSAMB11 devices does not properly restrict link-layer data length on reception, allowing attackers in radio range to cause a denial of service (crash) via a crafted packet.

NVD description · AI analysis pending
6.5<1%
  • microchip atmsamb11 blusdk smart
Full article908 words · extracted from securityaffairs.com · click to collapse

Pierluigi Paganini February 15, 2020

Security experts have discovered multiple flaws, dubbed SweynTooth, in the Bluetooth Low Energy (BLE) implementations of major system-on-a-chip (SoC) vendors.

A group of researchers has discovered multiple vulnerabilities, tracked as SweynTooth, in the Bluetooth Low Energy (BLE) implementations of major system-on-a-chip (SoC) vendors.

The group was composed of researchers Matheus E. Garbelini, Sudipta Chattopadhyay, and Chundong Wang from the Singapore University of Technology and Design.

The protocol Bluetooth Low Energy (BLE) was released in 2010 and it is designed to implement a new generation of services for mobile applications. The protocol specifically addresses power consumption of new applications, trying to reduce the draining of batteries in a condition of constantly transmitting signals.

Now experts found 12 vulnerabilities in the BLE software development kits (SDKs) of seven SoC vendors (Texas Instruments, NXP, Cypress, Dialog Semiconductors, Microchip, STMicroelectronics and Telink Semiconductor) that could be exploited to hack into various smart devices, including devices and environmental tracking or sensing systems.

Experts revealed that they have also identified several medical and logistics products that could be affected by the SweynTooth flaws.

The researchers already reported the flaws to the vendors, and most of them have already addressed them the issues

“SweynTooth captures a family of 12 vulnerabilities (more under non-disclosure) across different BLE software development kits (SDKs) of seven major system-on-a-chip (SoC) vendors.” reads the analysis published by the researchers. “The vulnerabilities expose flaws in specific BLE SoC implementations that allow an attacker in radio range to trigger deadlocks, crashes and buffer overflows or completely bypass security depending on the circumstances.”

Experts confirmed that more issues are still under disclosure and that the list of impacted SoC vendors is longer, and the number of IoT products designed on top of vulnerable SoCs still need independent patches from their respective vendors.

“SweynTooth highlights concrete flaws in the BLE stack certification process. We envision substantial amendments to the BLE stack certification to avoid SweynTooth style security flaws. We also urge SoC vendors and IoT product manufacturers to be aware of such security issues and to initiate focused effort in security testing.” continues the experts.

Experts classified the SweynTooth flaws according to their types and their behaviours on the vulnerable devices, below the classes defined by the experts:

  • Crash: Vulnerabilities that remotely trigger hard faults forcing the device crash. Typically, these issues trigger memory corruption, such as a buffer overflow on BLE reception buffer.
  • Deadlock: Vulnerabilities that affect the availability of the BLE connection without causing a hard fault or memory corruption. These issues usually occur due to some improper synchronization between user code and the SDK firmware distributed by the SoC vendor,
  • Security Bypass: Vulnerabilities that could be exploited by attackers in radio range to bypass the latest secure pairing mode of BLE. These issues are particularly dangerous because an attacker in the radio range has arbitrary read or write access to device’s functions.

“The exploitation of the vulnerabilities translates to dangerous attack vectors against many IoT products released in 2018-2019. At first glance, most of the vulnerabilities affect product’s availability by allowing them to be remotely restarted, deadlocked or having their security bypassed.  “continues the experts.

Making a quick search on the Bluetooth Listing Search site, experts discovered that around 480 product listings employ the affected SoCs, each of them containing several products.

A vulnerability named Link Layer Length Overflow impacts Cypress PSoC4/6 BLE Component 3.41/2.60 (CVE-2019-16336) and NXP KW41Z 3.40 SDK (CVE-2019-17519). The issue initially causes denial of service (DoS), but “attackers could reverse engineer products firmware to possibly leverage remote execution,” the researchers say.

Below the list of the flaws:

  • Link Layer LLID deadlock flaws, deadlock issued that affect Cypress (CVE-2019-17061) and NXP devices (CVE-2019-17060). The issues impact the BLE communication between devices.
  • Truncated L2CAP (CVE-2019-17517) flaw, a crash issue that affects Dialog DA14580 devices running SDK 5.0.4 or earlier. The issue could trigger a DoS condition causing the crash of the device, the same as Silent Length Overflow (CVE-2019-17518), which affects Dialog DA14680 devices.
  • Invalid Connection Request (CVE-2019-19195), a DoS issue that affects the Texas Instruments CC2640R2 BLE-STACK and CC2540 SDKs. A similar issue is the Unexpected Public Key Crash (CVE-2019-17520) and affects Texas Instruments CC2640R2 BLE-STACK-SDK could lead to DoS and product restarts.
  • Sequential ATT Deadlock (CVE-2019-19192), a deadlock issue that affects STMicroelectronics WB55 SDK V1.3.0 and earlier. Invalid L2CAP fragment (CVE-2019-19195) that could be exploited by a remote attacker to restart running Microchip ATMSAMB11 BluSDK Smart v6.2 and earlier.
  • The Key Size Overflow vulnerability (CVE-2019-19196), a crash issue that impacts all Telink Semiconductor BLE SDKs.
  • The security bypass flaw (CVE-2019-19194) in products using the Telink SMP implementation, which could be abused to completely bypass security in BLE products.

Below two video PoCs published by the experts that show the exploitations of the issues in some products:

At the time of the report. Dialog, Microchip and STMicroelectroncs have yet to release patches to address the flaws in the affected products.

“Our findings expose some fundamental attack vectors against certified and recertified BLE Stacks which are supposed to be ‘safe’ against such flaws. We carefully investigated the reasons that might explain the presence of SweynTooth vulnerabilities on the affected SoCs. We believe this is due to the imposed isolation between the link layer and other Bluetooth protocols, via the Host Controller Interface (HCI) protocol,” the researchers conclude.

[adrotate banner=”9″] [adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – SweynTooth, hacking)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/97890/hacking/sweyntooth-bluetooth-flaws.html