Infineon manufactures embedded semiconductor components and firmware, with observed vulnerability patterns centered on its Bluetooth mesh software development kit, secure-element firmware stacks, and cryptographic libraries. The durable signal clusters around memory-safety issues, particularly buffer-boundary violations and out-of-bounds writes, reflecting the low-level and performance-sensitive nature of firmware and cryptographic implementations. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Infineon over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-31364HIGH Cypress : https://www.infineon.com/ Cypress Bluetooth Mesh SDK BSA0107_05.01.00-BX8-AMESH-08 is affected by: Buffer Overflow. The impact is: execute arbitrary code (remote). The co | Feb 1, 2023 | 8.8 | 27 | NO | NO |
CVE-2022-31363HIGH Cypress : https://www.infineon.com/ Cypress Bluetooth Mesh SDK BSA0107_05.01.00-BX8-AMESH-08 is affected by: Buffer Overflow. The impact is: execute arbitrary code (remote). The co | Feb 1, 2023 | 8.8 | 27 | NO | NO |
CVE-2017-15361MEDIUM The Infineon RSA library 1.02.013 in Infineon Trusted Platform Module (TPM) firmware, such as versions before 0000000000000422 - 4.34, before 000000000000062b - 6.43, and before 00 | Oct 16, 2017 | 5.9 | 26 | NO | NO |
CVE-2017-9633HIGH An Improper Restriction of Operations within the Bounds of a Memory Buffer issue was discovered in the Continental AG Infineon S-Gold 2 (PMB 8876) chipset on BMW several models pro | Aug 7, 2017 | 8.8 | 26 | NO | NO |
CVE-2017-9647MEDIUM A Stack-Based Buffer Overflow issue was discovered in the Continental AG Infineon S-Gold 2 (PMB 8876) chipset on BMW several models produced between 2009-2010, Ford a limited numbe | Aug 7, 2017 | 6.6 | 21 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Infineon.
Media articles that mention a CVE ID that affects a product developed by Infineon — matched by CVE ID, not by vendor name.