TI
TI Simplelink Cc32xx Software Development KIT: vulnerabilities and CVEs
TI Simplelink Cc32xx Software Development KIT has 10 published vulnerabilities, 0 of them in the last 12 months. 2 are rated critical and 0 are listed by CISA as actively exploited.
CVEs10
Last 12 months0
Critical2
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-27504 | High (7.8) | 0.28% | — | Nov 21, 2023 | Texas Instruments devices running FREERTOS, malloc returns a valid pointer to a small buffer on extremely large values, which can trigger an integer overflow vulnerability in 'malloc' for FreeRTOS, resulting in code… |
| CVE-2021-27502 | High (7.8) | 0.28% | — | Nov 21, 2023 | Texas Instruments TI-RTOS, when configured to use HeapMem heap(default), malloc returns a valid pointer to a small buffer on extremely large values, which can trigger an integer overflow vulnerability in… |
| CVE-2021-27429 | High (7.8) | 0.28% | — | Nov 20, 2023 | Texas Instruments TI-RTOS returns a valid pointer to a small buffer on extremely large values. This can trigger an integer overflow vulnerability in 'HeapTrack_alloc' and result in code execution. |
| CVE-2021-22636 | High (7.8) | 0.28% | — | Nov 20, 2023 | Texas Instruments TI-RTOS, when configured to use HeapMem heap(default), malloc returns a valid pointer to a small buffer on extremely large values, which can trigger an integer overflow vulnerability in… |
| CVE-2021-21966 | Medium (5.3) | 1.4% | — | Feb 16, 2022 | An information disclosure vulnerability exists in the HTTP Server /ping.html functionality of Texas Instruments CC3200 SimpleLink Solution NWP 2.9.0.0. A specially-crafted HTTP request can lead to an uninitialized read.… |
| CVE-2021-22677 | High (7.8) | 0.30% | — | May 7, 2021 | An integer overflow exists in the APIs of the host MCU while trying to connect to a WIFI network may lead to issues such as a denial-of-service condition or code execution on the SimpleLink Wi-Fi (MSP432E4 SDK:… |
| CVE-2021-22673 | High (8) | 1.2% | — | May 7, 2021 | The affected product is vulnerable to stack-based buffer overflow while processing over-the-air firmware updates from the CDN server, which may allow an attacker to remotely execute code on the SimpleLink Wi-Fi… |
| CVE-2021-22671 | Critical (9.8) | 1.8% | — | May 7, 2021 | Multiple integer overflow issues exist while processing long domain names, which may allow an attacker to remotely execute code on the SimpleLink Wi-Fi (MSP432E4 SDK: v4.20.00.12 and prior, CC32XX SDK v4.30.00.06 and… |
| CVE-2021-22679 | Critical (9.8) | 1.8% | — | May 7, 2021 | The affected product is vulnerable to an integer overflow while processing HTTP headers, which may allow an attacker to remotely execute code on the SimpleLink Wi-Fi (MSP432E4 SDK: v4.20.00.12 and prior, CC32XX SDK… |
| CVE-2021-22675 | High (7.2) | 1.4% | — | May 7, 2021 | The affected product is vulnerable to integer overflow while parsing malformed over-the-air firmware update files, which may allow an attacker to remotely execute code on SimpleLink Wi-Fi (MSP432E4 SDK: v4.20.00.12 and… |
Other products by TI
Simplelink Cc26xx Software Development KIT · 9Simplelink Msp432e4 Software Development KIT · 5Simplelink Cc13x2 Software Development KIT · 5Cc3200 Software Development KIT · 5Simplelink Cc13x0 Software Development KIT · 5Cc3100 Software Development KIT · 5Simplelink Msp432e401y · 4Simplelink Cc13xx Software Development KIT · 4Real-time Operating System · 4Simplelink Msp432e411y · 4Z-stack · 4Omap L138 Firmware · 3