MEDIUM · 5.3

CVE-2021-21966

An information disclosure vulnerability exists in the HTTP Server /ping.html functionality of Texas Instruments CC3200 SimpleLink Solution NWP 2.9.0.0. A specially-crafted HTTP request can lead to an ...

Vulnerability Description

An information disclosure vulnerability exists in the HTTP Server /ping.html functionality of Texas Instruments CC3200 SimpleLink Solution NWP 2.9.0.0. A specially-crafted HTTP request can lead to an uninitialized read. An attacker can send an HTTP request to trigger this vulnerability.

CVSS Score

5.3

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
LOW
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
TiSimplelink Cc32Xx Software Development Kit< 5.30.00.08
TiCc3120-
TiCc3130-
TiCc3135-
TiCc3220R-
TiCc3220S-
TiCc3220Sf-
TiCc3230S-
TiCc3230Sf-
TiCc3235S-
TiCc3235Sf-
TiCc3100 Firmware< 1.0.1.15-2.15.0.1
TiCc3100-
TiCc3200 Firmware< 1.0.1.15-2.15.0.1
TiCc3200-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-21966?

CVE-2021-21966 is a vulnerability with a CVSS score of 5.3 (MEDIUM). An information disclosure vulnerability exists in the HTTP Server /ping.html functionality of Texas Instruments CC3200 SimpleLink Solution NWP 2.9.0.0. A specially-crafted HTTP request can lead to an ...

How severe is CVE-2021-21966?

CVE-2021-21966 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-21966?

Check the references section above for vendor advisories and patch information. Affected products include: Ti Simplelink Cc32Xx Software Development Kit, Ti Cc3120, Ti Cc3130, Ti Cc3135, Ti Cc3220R.