Learn about CVE-2019-19192, a vulnerability in STMicroelectronics BLE Stack version 1.3.1 for STM32WB5x devices that allows attackers to cause system crashes. Find mitigation steps and prevention measures here.
The STMicroelectronics BLE Stack version 1.3.1 for STM32WB5x devices has a vulnerability in its Bluetooth Low Energy implementation that allows attackers to cause a system crash or deadlock.
Understanding CVE-2019-19192
This CVE involves a flaw in the STMicroelectronics BLE Stack version 1.3.1 for STM32WB5x devices related to handling consecutive Attribute Protocol (ATT) requests.
What is CVE-2019-19192?
The vulnerability in the BLE Stack version 1.3.1 allows attackers within radio range to exploit the system by sending carefully crafted packets, leading to an event deadlock or crash.
The Impact of CVE-2019-19192
Attackers can exploit this vulnerability to disrupt the system's operation, potentially causing a crash or deadlock, affecting the device's availability and performance.
Technical Details of CVE-2019-19192
The technical aspects of this CVE provide insight into the vulnerability's specifics.
Vulnerability Description
The flaw in the STMicroelectronics BLE Stack version 1.3.1 allows attackers to disrupt the system by sending maliciously crafted packets, resulting in a crash or deadlock.
Affected Systems and Versions
Exploitation Mechanism
Attackers exploit the vulnerability by sending carefully crafted packets within radio range, triggering consecutive ATT requests that the system fails to handle correctly.
Mitigation and Prevention
Protecting systems from CVE-2019-19192 requires immediate actions and long-term security practices.
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates