« Volver al listado

CVE-2021-21966

Estado: ModificadaMedia (5.3)—

An information disclosure vulnerability exists in the HTTP Server /ping.html functionality of Texas Instruments CC3200 SimpleLink Solution NWP 2.9.0.0. A specially-crafted HTTP request can lead to an uninitialized read. An attacker can send an HTTP request to trigger this vulnerability.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (3)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2021-21966",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Secondary",
        "source": "talos-cna@cisco.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 5.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 3.9
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "talos-cna@cisco.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "Texas Instruments",
          "versions": [
            {
              "status": "affected",
              "version": "Texas Instruments CC3200 SimpleLink Solution NWP 2.9.0.0,Sealevel Systems, Inc. SeaConnect 370W v1.3.34"
            }
          ]
        }
      ]
    }
  ],
  "published": "2022-02-16T17:15:10.353",
  "references": [
    {
      "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2021-1393",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "talos-cna@cisco.com"
    },
    {
      "url": "https://www.ti.com/lit/an/swra740/swra740.pdf?ts=1645536893264&",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "nvd@nist.gov"
    },
    {
      "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2021-1393",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "talos-cna@cisco.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-457"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-908"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An information disclosure vulnerability exists in the HTTP Server /ping.html functionality of Texas Instruments CC3200 SimpleLink Solution NWP 2.9.0.0. A specially-crafted HTTP request can lead to an uninitialized read. An attacker can send an HTTP request to trigger this vulnerability."
    },
    {
      "lang": "es",
      "value": "Se presenta una vulnerabilidad de divulgación de información en la funcionalidad HTTP Server /ping.html de Texas Instruments CC3200 SimpleLink Solution NWP versión 2.9.0.0. Una petición HTTP especialmente diseñada puede conllevar a una lectura no inicializada. Un atacante puede enviar una petición HTTP para desencadenar esta vulnerabilidad"
    }
  ],
  "lastModified": "2026-06-17T03:36:27.920",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:ti:simplelink_cc32xx_software_development_kit:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "579C3D60-5AA8-41AB-B7C1-340A300CAE39",
              "versionEndExcluding": "5.30.00.08"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:ti:cc3120:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "253510AE-F0BE-45A3-B3C5-0B7F8074317A"
            },
            {
              "criteria": "cpe:2.3:h:ti:cc3130:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "0513D674-B4DF-4BD5-83C6-380B54316B29"
            },
            {
              "criteria": "cpe:2.3:h:ti:cc3135:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "21FD4E05-1521-4F3E-ACEC-FE14E92820DE"
            },
            {
              "criteria": "cpe:2.3:h:ti:cc3220r:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "D436F6E3-B044-457E-B67D-9C76105F0847"
            },
            {
              "criteria": "cpe:2.3:h:ti:cc3220s:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "EE6E103B-F34A-477C-907D-B4EAE295D90E"
            },
            {
              "criteria": "cpe:2.3:h:ti:cc3220sf:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "71ABA01C-4CB1-4DD5-9263-79A58BED3A9B"
            },
            {
              "criteria": "cpe:2.3:h:ti:cc3230s:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "E34FD25E-D5C2-40F0-81E2-A8A102934E8C"
            },
            {
              "criteria": "cpe:2.3:h:ti:cc3230sf:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "3408EEBE-25EC-4CEA-8E96-DCFF7C66B3F6"
            },
            {
              "criteria": "cpe:2.3:h:ti:cc3235s:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "370E65A3-17A4-4E05-BB4A-6C09BB5249CA"
            },
            {
              "criteria": "cpe:2.3:h:ti:cc3235sf:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "B06F9E6A-690D-4E95-ADD4-927995EE5523"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:ti:cc3100_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "674D8056-EDA3-43F5-8859-08FBF3AED523",
              "versionEndExcluding": "1.0.1.15-2.15.0.1"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:ti:cc3100:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "CFD28F25-EC13-4994-B040-D2F5F1D1C1A2"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:ti:cc3200_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8374620E-9070-4105-B6DB-A974085345A9",
              "versionEndExcluding": "1.0.1.15-2.15.0.1"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:ti:cc3200:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "E1738237-A64A-40A3-B201-7E0005CCA3A2"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "talos-cna@cisco.com"
}