Vulnerabilities > TI

DATE CVE VULNERABILITY TITLE RISK
2021-09-20 CVE-2020-16630 Incorrect Authorization vulnerability in TI products
TI’s BLE stack caches and reuses the LTK’s property for a bonded mobile.
high complexity
ti CWE-863
6.8
2021-09-07 CVE-2021-34149 Unspecified vulnerability in TI Cc256Xcqfn-Em Firmware
The Bluetooth Classic implementation on the Texas Instruments CC256XCQFN-EM does not properly handle the reception of continuous LMP_AU_Rand packets, allowing attackers in radio range to trigger a denial of service (deadlock) of the device by flooding it with LMP_AU_Rand packets after the paging procedure.
low complexity
ti
6.5
2021-05-07 CVE-2021-22677 Unspecified vulnerability in TI products
An integer overflow exists in the APIs of the host MCU while trying to connect to a WIFI network may lead to issues such as a denial-of-service condition or code execution on the SimpleLink Wi-Fi (MSP432E4 SDK: v4.20.00.12 and prior, CC32XX SDK v4.30.00.06 and prior, CC13X0 SDK versions prior to v4.10.03, CC13X2 and CC26XX SDK versions prior to v4.40.00, CC3200 SDK v1.5.0 and prior, CC3100 SDK v1.3.0 and prior).
local
low complexity
ti
7.8
2021-05-07 CVE-2021-22671 Unspecified vulnerability in TI products
Multiple integer overflow issues exist while processing long domain names, which may allow an attacker to remotely execute code on the SimpleLink Wi-Fi (MSP432E4 SDK: v4.20.00.12 and prior, CC32XX SDK v4.30.00.06 and prior, CC13X0 SDK versions prior to v4.10.03, CC13X2 and CC26XX SDK versions prior to v4.40.00, CC3200 SDK v1.5.0 and prior, CC3100 SDK v1.3.0 and prior).
network
low complexity
ti
critical
9.8
2021-05-07 CVE-2021-22673 Out-of-bounds Write vulnerability in TI products
The affected product is vulnerable to stack-based buffer overflow while processing over-the-air firmware updates from the CDN server, which may allow an attacker to remotely execute code on the SimpleLink Wi-Fi (MSP432E4 SDK: v4.20.00.12 and prior, CC32XX SDK v4.30.00.06 and prior, CC13X0 SDK versions prior to v4.10.03, CC13X2 and CC26XX SDK versions prior to v4.40.00, CC3200 SDK v1.5.0 and prior, CC3100 SDK v1.3.0 and prior).
network
low complexity
ti CWE-787
8.0
2021-05-07 CVE-2021-22675 Unspecified vulnerability in TI products
The affected product is vulnerable to integer overflow while parsing malformed over-the-air firmware update files, which may allow an attacker to remotely execute code on SimpleLink Wi-Fi (MSP432E4 SDK: v4.20.00.12 and prior, CC32XX SDK v4.30.00.06 and prior, CC13X0 SDK versions prior to v4.10.03, CC13X2 and CC26XX SDK versions prior to v4.40.00, CC3200 SDK v1.5.0 and prior, CC3100 SDK v1.3.0 and prior).
network
low complexity
ti
7.2
2021-05-07 CVE-2021-22679 Unspecified vulnerability in TI products
The affected product is vulnerable to an integer overflow while processing HTTP headers, which may allow an attacker to remotely execute code on the SimpleLink Wi-Fi (MSP432E4 SDK: v4.20.00.12 and prior, CC32XX SDK v4.30.00.06 and prior, CC13X0 SDK versions prior to v4.10.03, CC13X2 and CC26XX SDK versions prior to v4.40.00, CC3200 SDK v1.5.0 and prior, CC3100 SDK v1.3.0 and prior).
network
low complexity
ti
critical
9.8
2021-01-26 CVE-2021-3285 Improper Certificate Validation vulnerability in TI Code Composer Studio Intgrated Development Environment
jxbrowser in TI Code Composer Studio IDE 8.x through 10.x before 10.1.1 does not verify X.509 certificates for HTTPS.
network
low complexity
ti CWE-295
5.3
2020-10-27 CVE-2020-27892 Unspecified vulnerability in TI Z-Stack 3.0.1
The Zigbee protocol implementation on Texas Instruments CC2538 devices with Z-Stack 3.0.1 does not properly process a ZCL Discover Commands Received Response message or a ZCL Discover Commands Generated Response message.
network
low complexity
ti
7.5
2020-10-27 CVE-2020-27891 Unspecified vulnerability in TI Z-Stack 3.0.1
The Zigbee protocol implementation on Texas Instruments CC2538 devices with Z-Stack 3.0.1 does not properly process a ZCL Read Reporting Configuration Response message.
network
low complexity
ti
7.5