CVE-2021-22675 Vulnerability Details

  /     /     /  

CVE-2021-22675 Metadata Quick Info

CVE Published: 07/05/2021 | CVE Updated: 03/08/2024 | CVE Year: 2021
Source: icscert | Vendor: n/a | Product: SimpleLink Wi-Fi, MSP432, CC13XX, CC26XX, CC32XX, CC3100
Status : PUBLISHED

CVE-2021-22675 Description

The affected product is vulnerable to integer overflow while parsing malformed over-the-air firmware update files, which may allow an attacker to remotely execute code on SimpleLink Wi-Fi (MSP432E4 SDK: v4.20.00.12 and prior, CC32XX SDK v4.30.00.06 and prior, CC13X0 SDK versions prior to v4.10.03, CC13X2 and CC26XX SDK versions prior to v4.40.00, CC3200 SDK v1.5.0 and prior, CC3100 SDK v1.3.0 and prior).

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID: CWE-190
CWE Name: INTEGER OVERFLOW OR WRAPAROUND CWE-190
Source: n/a

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).