Cypress develops wireless connectivity solutions for embedded systems and IoT devices, including microcontrollers and firmware components such as the CYW series wireless modules used across a range of connected applications. The recurring vulnerability signal centers on memory-safety and input-handling weaknesses including buffer overflows, out-of-bounds writes, and OS command injection, alongside firmware and information-disclosure issues characteristic of low-level embedded and wireless components. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cypress over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-47415HIGH Cypress Solutions CTM-200 v2.7.1.5600 and below was discovered to contain an OS command injection vulnerability via the cli_text parameter. | Mar 7, 2024 | 7.5 | 30 | NO | NO |
CVE-2018-19860HIGH Broadcom firmware before summer 2014 on Nexus 5 BCM4335C0 2012-12-11, Raspberry Pi 3 BCM43438A1 2014-06-02, and unspecifed other devices does not properly restrict LMP commnds and | Jun 7, 2019 | 8.8 | 28 | NO | NO |
CVE-2019-13916HIGH An issue was discovered in Cypress (formerly Broadcom) WICED Studio 6.2 CYW20735B1 and CYW20819A1. As a Bluetooth Low Energy (BLE) packet is received, it is copied into a Heap (Thr | Apr 13, 2020 | 8.8 | 27 | NO | NO |
CVE-2019-18614HIGH On the Cypress CYW20735 evaluation board, any data that exceeds 384 bytes is copied and causes an overflow. This is because the maximum BLOC buffer size for sending and receiving d | Jun 16, 2020 | 7.8 | 25 | NO | NO |
CVE-2020-11957HIGH The Bluetooth Low Energy implementation in Cypress PSoC Creator BLE 4.2 component versions before 3.64 generates a random number (Pairing Random) with significantly less entropy th | Jun 9, 2020 | 7.5 | 24 | NO | NO |
CVE-2019-17061MEDIUM The Bluetooth Low Energy (BLE) stack implementation on Cypress PSoC 4 through 3.62 devices does not properly restrict the BLE Link Layer header and executes certain memory contents | Feb 10, 2020 | 6.5 | 23 | NO | NO |
CVE-2021-34147MEDIUM The Bluetooth Classic implementation in the Cypress WICED BT stack through 2.9.0 for CYW20735B1 does not properly handle the reception of a malformed LMP timing accuracy response f | Sep 7, 2021 | 6.5 | 21 | NO | NO |
CVE-2021-34146MEDIUM The Bluetooth Classic implementation in the Cypress CYW920735Q60EVB does not properly handle the reception of continuous unsolicited LMP responses, allowing attackers in radio rang | Sep 7, 2021 | 6.5 | 21 | NO | NO |
CVE-2019-16336MEDIUM The Bluetooth Low Energy implementation in Cypress PSoC 4 BLE component 3.61 and earlier processes data channel frames with a payload length larger than the configured link layer m | Feb 12, 2020 | 6.5 | 21 | NO | NO |
CVE-2021-34148MEDIUM The Bluetooth Classic implementation in the Cypress WICED BT stack through 2.9.0 for CYW20735B1 devices does not properly handle the reception of LMP_max_slot with a greater ACL Le | Sep 7, 2021 | 6.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cypress.
Media articles that mention a CVE ID that affects a product developed by Cypress — matched by CVE ID, not by vendor name.