Simplelink Cc26xx Software Development Kit
Vendor:
First CVE: May 7, 2021 · Active for 5 years
9
Total CVEs
More Total CVEs than 88% of tracked products
4.5
Avg CVEs / Year
Higher CVE frequency than 88% of tracked products
8.2
Avg CVSS
Higher Avg CVSS than 74% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Simplelink Cc26xx Software Development Kit over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 7, 2021
5 years ago
Most Recent CVE
Nov 21, 2023
980 days ago
CVE Severity & Scoring
Simplelink Cc26xx Software Development Kit9 CVEs
78%
22%
All CVEs353,240 CVEs
45%
40%
11%
HighCritical
Attack Vector
Local5 (55.6%)
Network4 (44.4%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None8 (88.9%)
Unknown0 (0.0%)
Required1 (11.1%)
Privileges Required
Low6 (66.7%)
High1 (11.1%)
None2 (22.2%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-22671CRITICAL Multiple integer overflow issues exist while processing long domain names, which may allow an attacker to remotely execute code on the SimpleLink Wi-Fi (MSP432E4 SDK: v4.20.00.12 a | May 7, 2021 | 9.8 | 31 | NO | NO |
CVE-2021-22679CRITICAL The affected product is vulnerable to an integer overflow while processing HTTP headers, which may allow an attacker to remotely execute code on the SimpleLink Wi-Fi (MSP432E4 SDK: | May 7, 2021 | 9.8 | 30 | NO | NO |
CVE-2021-22677HIGH An integer overflow exists in the APIs of the host MCU while trying to connect to a WIFI network may lead to issues such as a denial-of-service condition or code execution on the S | May 7, 2021 | 7.8 | 25 | NO | NO |
CVE-2021-22673HIGH The affected product is vulnerable to stack-based buffer overflow while processing over-the-air firmware updates from the CDN server, which may allow an attacker to remotely execut | May 7, 2021 | 8.0 | 25 | NO | NO |
CVE-2021-22675HIGH The affected product is vulnerable to integer overflow while parsing malformed over-the-air firmware update files, which may allow an attacker to remotely execute code on SimpleLin | May 7, 2021 | 7.2 | 24 | NO | NO |
CVE-2021-22636HIGH
Texas Instruments TI-RTOS, when configured to use HeapMem heap(default), malloc returns a valid pointer to a small buffer on extremely large values, which can trigger an int | Nov 20, 2023 | 7.8 | 22 | NO | NO |
CVE-2021-27504HIGH Texas Instruments devices running FREERTOS, malloc returns a valid
pointer to a small buffer on extremely large values, which can trigger
an integer overflow vulnerability in 'ma | Nov 21, 2023 | 7.8 | 21 | NO | NO |
CVE-2021-27502HIGH Texas Instruments TI-RTOS, when configured to use HeapMem heap(default),
malloc returns a valid pointer to a small buffer on extremely large
values, which can trigger an integer | Nov 21, 2023 | 7.8 | 21 | NO | NO |
CVE-2021-27429HIGH
Texas Instruments TI-RTOS returns a valid pointer to a small buffer on extremely large values. This can trigger an integer overflow vulnerability in 'HeapTrack_alloc' and result i | Nov 20, 2023 | 7.8 | 21 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (9 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (9 CVEs).
Media Mentions
Signals from CVEs in this product scope (9 CVEs).
Top CNAs Publishing CVEs For Simplelink Cc26xx Software Development Kit
Top CWEs
Versions
No cataloged versions.