Vulnerabilities > Cypress > High

DATE CVE VULNERABILITY TITLE RISK
2020-06-16 CVE-2019-18614 Out-of-bounds Write vulnerability in Cypress Cyw20735 Firmware
On the Cypress CYW20735 evaluation board, any data that exceeds 384 bytes is copied and causes an overflow.
local
low complexity
cypress CWE-787
7.8
2020-06-09 CVE-2020-11957 Insufficient Entropy vulnerability in Cypress Psoc 4.2 BLE
The Bluetooth Low Energy implementation in Cypress PSoC Creator BLE 4.2 component versions before 3.64 generates a random number (Pairing Random) with significantly less entropy than the specified 128 bits during BLE pairing.
high complexity
cypress CWE-331
7.5
2020-04-13 CVE-2019-13916 Out-of-bounds Write vulnerability in Cypress Wiced Studio 6.2
An issue was discovered in Cypress (formerly Broadcom) WICED Studio 6.2 CYW20735B1 and CYW20819A1.
low complexity
cypress CWE-787
8.8
2019-06-07 CVE-2018-19860 Incorrect Permission Assignment for Critical Resource vulnerability in multiple products
Broadcom firmware before summer 2014 on Nexus 5 BCM4335C0 2012-12-11, Raspberry Pi 3 BCM43438A1 2014-06-02, and unspecifed other devices does not properly restrict LMP commnds and executes certain memory contents upon receiving an LMP command, as demonstrated by executing an HCI command.
low complexity
broadcom cypress CWE-732
8.8