CVE-2019-17520 describes a denial-of-service vulnerability in the Bluetooth Low Energy implementation of Texas Instruments SDKs through version 3.30.00.20 for CC2640R2 devices. An attacker within radio range can exploit this by sending crafted SM Public Key packets, causing the device to crash. This medium-severity vulnerability (CVSS 6.5) requires adjacent network access and low attack complexity, leading to a high impact on availability. While not actively exploited in the wild and lacking public exploit code, it has garnered some community discussion and media coverage as part of the broader "SweynTooth" vulnerability collection.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 3.30.00.20CPE matchmatch criteria | cpe:2.3:a:ti:cc2640r2_software_development_kit:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.