Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Nordicsemi

First CVE: Jul 7, 2020Active for: 6 yearsTotal CVEs: 6

Nordic Semiconductor manufactures Bluetooth Low Energy wireless system-on-chip (SoC) components and software development kits that are embedded in IoT devices, wearables, and mobile peripherals across consumer and industrial deployments. Its disclosed vulnerabilities center on wireless protocol implementation and firmware handling in products such as the nRF52840 chipset and associated mesh and Android libraries, with recurrent weakness classes including observable discrepancies in wireless behavior, out-of-bounds writes, cleartext transmission of sensitive data, and resource-consumption issues that reflect the constraints and complexity of low-power wireless stacks. Current severity and exploitation activity are shown alongside this summary.

FAUCET AI Generated
6
Total CVEs
More Total CVEs than 86% of tracked vendors
0.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 2% of tracked vendors
7.0
Avg CVSS Score
Higher Avg CVSS Score than 49% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Nordicsemi over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 7, 2020
6 years ago
Most Recent CVE
Feb 8, 2023
1,266 days ago

Products(5 total)

Top CVEs

Signals from CVEs in this vendor scope (6 CVEs).

6 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-35624HIGH
In Nordic nRF5 SDK for Mesh 5.0, a heap overflow vulnerability can be triggered by sending a series of segmented packets with SegO > SegN
Aug 15, 20228.827NONO
CVE-2022-35623HIGH
In Nordic nRF5 SDK for Mesh 5.0, a heap overflow vulnerability can be triggered by sending a series of segmented control packets and access packets with the same SeqAuth
Aug 15, 20228.827NONO
CVE-2020-15509MEDIUM
Nordic Semiconductor Android BLE Library through 2.2.1 and DFU Library through 1.10.4 for Android (as used by nRF Connect and other applications) can engage in unencrypted communic
Jul 7, 20206.523NONO
CVE-2022-40480MEDIUM
Nordic Semiconductor, Microchip Technology NRF5340-DK DT100112 was discovered to contain an issue which allows attackers to cause a Denial of Service (DoS) via a crafted ConReq pac
Feb 8, 20236.521NONO
CVE-2020-27211MEDIUM
Nordic Semiconductor nRF52840 devices through 2020-10-19 have improper protection against physical side channels. The flash read-out protection (APPROTECT) can be bypassed by injec
May 21, 20215.719NONO
CVE-2021-29415MEDIUM
The elliptic curve cryptography (ECC) hardware accelerator, part of the ARM® TrustZone® CryptoCell 310, contained in the NordicSemiconductor nRF52840 through 2021-03-29 has a non-c
May 21, 20215.519NONO
View all 6 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products6 CVEs
67%
33%
Severity distribution among all CVEs353,240 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local1 (16.7%)
Network0 (0.0%)
Unknown0 (0.0%)
Physical1 (16.7%)
Adjacent Network4 (66.7%)
Attack Complexity
Low5 (83.3%)
High1 (16.7%)
Unknown0 (0.0%)
User Interaction
None6 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low1 (16.7%)
High0 (0.0%)
None5 (83.3%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (6 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Nordicsemi.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Nordicsemi — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Nordicsemi's Products

View all 1 CNAs →

Top CWEs