CVSS2
Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
COMPLETE
AV:A/AC:L/Au:N/C:N/I:N/A:C
CVSS3
Attack Vector
ADJACENT
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
AI Score
Confidence
High
EPSS
Percentile
29.0%
The Bluetooth Low Energy (BLE) stack implementation on the NXP KW41Z (based on the MCUXpresso SDK with Bluetooth Low Energy Driver 2.2.1 and earlier) does not properly restrict the BLE Link Layer header and executes certain memory contents upon receiving a packet with a Link Layer ID (LLID) equal to zero. This allows attackers within radio range to cause deadlocks, cause anomalous behavior in the BLE state machine, or trigger a buffer overflow via a crafted BLE Link Layer frame.
Vendor | Product | Version | CPE |
---|---|---|---|
nxp | kw31z | - | cpe:2.3:h:nxp:kw31z:-:*:*:*:*:*:*:* |
nxp | kw34 | - | cpe:2.3:h:nxp:kw34:-:*:*:*:*:*:*:* |
nxp | kw35 | - | cpe:2.3:h:nxp:kw35:-:*:*:*:*:*:*:* |
nxp | kw36 | - | cpe:2.3:h:nxp:kw36:-:*:*:*:*:*:*:* |
nxp | kw37 | - | cpe:2.3:h:nxp:kw37:-:*:*:*:*:*:*:* |
nxp | kw38 | - | cpe:2.3:h:nxp:kw38:-:*:*:*:*:*:*:* |
nxp | kw39 | - | cpe:2.3:h:nxp:kw39:-:*:*:*:*:*:*:* |
nxp | kw41z | - | cpe:2.3:h:nxp:kw41z:-:*:*:*:*:*:*:* |
nxp | mcuxpresso_software_development_kit | * | cpe:2.3:a:nxp:mcuxpresso_software_development_kit:*:*:*:*:*:*:*:* |
CVSS2
Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
COMPLETE
AV:A/AC:L/Au:N/C:N/I:N/A:C
CVSS3
Attack Vector
ADJACENT
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
AI Score
Confidence
High
EPSS
Percentile
29.0%