Learn about CVE-2019-17519, a Bluetooth Low Energy vulnerability in NXP SDK up to version 2.2.1 for KW41Z devices enabling buffer overflow attacks. Find mitigation steps and affected systems here.
Bluetooth Low Energy vulnerability in NXP SDK up to version 2.2.1 for KW41Z devices allows buffer overflow attacks.
Understanding CVE-2019-17519
Bluetooth Low Energy vulnerability in NXP SDK for KW41Z devices enables buffer overflow attacks through crafted packets.
What is CVE-2019-17519?
Attackers within radio range can exploit a vulnerability in the Bluetooth Low Energy implementation on NXP SDK up to version 2.2.1 for KW41Z devices. This flaw arises due to inadequate restrictions on the Link Layer payload length, enabling the execution of a buffer overflow attack through a specifically crafted packet.
The Impact of CVE-2019-17519
Technical Details of CVE-2019-17519
Bluetooth Low Energy vulnerability in NXP SDK for KW41Z devices
Vulnerability Description
The Bluetooth Low Energy implementation on NXP SDK through 2.2.1 for KW41Z devices does not properly restrict the Link Layer payload length, allowing attackers in radio range to cause a buffer overflow via a crafted packet.
Affected Systems and Versions
Exploitation Mechanism
Mitigation and Prevention
Immediate Steps to Take
Patching and Updates