Vulnerability Description
Embedded systems based on Arduino before Rev3 allow remote attackers to send data to LEDs (directly connected to GPIO pins) via a laser, because of LED photosensitivity.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Arduino | Arduino Firmware | < rev3 |
| Arduino | Arduino | - |
References
- https://arxiv.org/abs/1907.00479Third Party Advisory
- https://arxiv.org/abs/1907.00479Third Party Advisory
FAQ
What is CVE-2019-13991?
CVE-2019-13991 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Embedded systems based on Arduino before Rev3 allow remote attackers to send data to LEDs (directly connected to GPIO pins) via a laser, because of LED photosensitivity.
How severe is CVE-2019-13991?
CVE-2019-13991 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-13991?
Check the references section above for vendor advisories and patch information. Affected products include: Arduino Arduino Firmware, Arduino Arduino.