CVE-2019-19192 is a medium-severity vulnerability affecting STMicroelectronics STM32WB5x devices utilizing the BLE Stack through version 1.3.1. It stems from improper handling of consecutive Attribute Protocol (ATT) requests in the Bluetooth Low Energy implementation, allowing attackers within radio range to trigger an event deadlock or device crash. The attack requires no user interaction or privileges, but is limited to adjacent network access. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community attention and media coverage as part of the broader "SweynTooth" bug collection.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.3.1CPE matchmatch criteria | cpe:2.3:a:st:wb55:*:*:*:*:*:*:*:* | ||
<= 1.3.1CPE matchmatch criteria | cpe:2.3:a:st:bluenrg-2:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.