CVE-2019-17518 describes a buffer overflow vulnerability in the Bluetooth Low Energy (BLE) implementation of Dialog Semiconductor SDK through 1.0.14.1081 for DA1468x devices, including products like the August Smart Lock. An attacker within radio range can exploit this by sending a crafted link layer packet with an oversized payload. Rated 6.5 MEDIUM, this vulnerability allows for a denial-of-service impact (A:H) with low attack complexity (AC:L) and no user interaction required (UI:N). While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), it has garnered significant community discussion and media coverage as part of the "SweynTooth" bug collection.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.0.14.1081CPE matchmatch criteria | cpe:2.3:a:dialog-semiconductor:software_development_kit:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.