Vulnerability Description
The Bluetooth Low Energy implementation on Microchip Technology BluSDK Smart through 6.2 for ATSAMB11 devices does not properly restrict link-layer data length on reception, allowing attackers in radio range to cause a denial of service (crash) via a crafted packet.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microchip | Atmsamb11 Blusdk Smart | <= 6.2 |
| Microchip | Atsamb11 | - |
References
- https://asset-group.github.io/disclosures/sweyntooth/Third Party Advisory
- https://www.microchip.com/wwwproducts/en/ATSAMB11ProductVendor Advisory
- https://asset-group.github.io/disclosures/sweyntooth/Third Party Advisory
- https://www.microchip.com/wwwproducts/en/ATSAMB11ProductVendor Advisory
FAQ
What is CVE-2019-19195?
CVE-2019-19195 is a vulnerability with a CVSS score of 6.5 (MEDIUM). The Bluetooth Low Energy implementation on Microchip Technology BluSDK Smart through 6.2 for ATSAMB11 devices does not properly restrict link-layer data length on reception, allowing attackers in radi...
How severe is CVE-2019-19195?
CVE-2019-19195 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-19195?
Check the references section above for vendor advisories and patch information. Affected products include: Microchip Atmsamb11 Blusdk Smart, Microchip Atsamb11.