Nordic Semiconductor manufactures Bluetooth Low Energy wireless system-on-chip (SoC) components and software development kits that are embedded in IoT devices, wearables, and mobile peripherals across consumer and industrial deployments. Its disclosed vulnerabilities center on wireless protocol implementation and firmware handling in products such as the nRF52840 chipset and associated mesh and Android libraries, with recurrent weakness classes including observable discrepancies in wireless behavior, out-of-bounds writes, cleartext transmission of sensitive data, and resource-consumption issues that reflect the constraints and complexity of low-power wireless stacks. Current severity and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Nordicsemi over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-35624HIGH In Nordic nRF5 SDK for Mesh 5.0, a heap overflow vulnerability can be triggered by sending a series of segmented packets with SegO > SegN | Aug 15, 2022 | 8.8 | 27 | NO | NO |
CVE-2022-35623HIGH In Nordic nRF5 SDK for Mesh 5.0, a heap overflow vulnerability can be triggered by sending a series of segmented control packets and access packets with the same SeqAuth | Aug 15, 2022 | 8.8 | 27 | NO | NO |
CVE-2020-15509MEDIUM Nordic Semiconductor Android BLE Library through 2.2.1 and DFU Library through 1.10.4 for Android (as used by nRF Connect and other applications) can engage in unencrypted communic | Jul 7, 2020 | 6.5 | 23 | NO | NO |
CVE-2022-40480MEDIUM Nordic Semiconductor, Microchip Technology NRF5340-DK DT100112 was discovered to contain an issue which allows attackers to cause a Denial of Service (DoS) via a crafted ConReq pac | Feb 8, 2023 | 6.5 | 21 | NO | NO |
CVE-2020-27211MEDIUM Nordic Semiconductor nRF52840 devices through 2020-10-19 have improper protection against physical side channels. The flash read-out protection (APPROTECT) can be bypassed by injec | May 21, 2021 | 5.7 | 19 | NO | NO |
CVE-2021-29415MEDIUM The elliptic curve cryptography (ECC) hardware accelerator, part of the ARM® TrustZone® CryptoCell 310, contained in the NordicSemiconductor nRF52840 through 2021-03-29 has a non-c | May 21, 2021 | 5.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Nordicsemi.
Media articles that mention a CVE ID that affects a product developed by Nordicsemi — matched by CVE ID, not by vendor name.