CVE-2019-17060 is a vulnerability in the Bluetooth Low Energy (BLE) stack of NXP KW41Z and related MCUXpresso SDK-based products. It allows an attacker within radio range to send a specially crafted BLE Link Layer frame, leading to deadlocks, anomalous BLE state machine behavior, or a buffer overflow. Rated as Medium severity (CVSS 6.5), this vulnerability requires no user interaction or privileges to exploit, but only affects availability. While not actively exploited in the wild and lacking public exploit code, it has garnered significant community discussion and media coverage as part of the broader "SweynTooth" vulnerability collection.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.2.1CPE matchmatch criteria | cpe:2.3:a:nxp:mcuxpresso_software_development_kit:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.