CVE-2018-16986
Severity CVSS v4.0:
Pending analysis
Type:
CWE-787
Out-of-bounds Write
Publication date:
06/11/2018
Last modified:
24/08/2020
Description
Texas Instruments BLE-STACK v2.2.1 for SimpleLink CC2640 and CC2650 devices allows remote attackers to execute arbitrary code via a malformed packet that triggers a buffer overflow.
Impact
Base Score 3.x
8.80
Severity 3.x
HIGH
Base Score 2.0
5.80
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:ti:ble-stack:*:*:*:*:*:*:*:* | 2.2.1 (including) | |
| cpe:2.3:h:ti:cc2640:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:ti:cc2650:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:ti:ble-stack:3.0.0:*:*:*:*:*:*:* | ||
| cpe:2.3:h:ti:cc2640r2f:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:ti:ble-stack:*:*:*:*:*:*:*:* | 2.3.3 (including) | |
| cpe:2.3:h:ti:cc1350:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://e2e.ti.com/support/wireless-connectivity/bluetooth/f/538/t/742827
- http://www.securityfocus.com/bid/105812
- http://www.securitytracker.com/id/1042018
- https://armis.com/bleedingbit/
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20181101-ap
- https://www.kb.cert.org/vuls/id/317277



