BLEEDINGBIT Bluetooth Vulnerabilities
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Affected platforms
The following platforms are known to be affected:
TI Wireless MCUs
Affected Texas Instruments products:
- TI Wireless MCUs - CC1350, CC2540, CC2541, CC2640, CC2640R2, CC2640R2F, CC2642R and CC2650
- BLE-STACK software suite - Version 2.2.1 or earlier
Affected Aruba products:
- Aruba access points - AP203RP, AP203RAP, AP-3xx and IAP-3xx series
- ArubaOS - Versions:
- 6.4.4.x prior to 6.4.4.20
- 6.5.3.x prior to 6.5.3.9
- 6.5.4.x prior to 6.5.4.9
- 8.x prior to 8.2.2.2
- 8.3.x prior to 8.3.0.4
- 6.4.4.x prior to 6.4.4.20
Affected Cisco products:
- Cisco Aironet access points - 1800i, 1810, 1815i, 1815m, 1815w and 4800 series
- Cisco Aironet outdoor access points - 1540 series
- Meraki access points - MR30H, MR33, MR42E, MR53E and MR74 series
Threat details
The first vulnerability (CVE-2018-16986) lies in how the affected micro-controllers handle specialised BLE packets known as advertising packets. When advertising packets are sent to an affected micro-controller they are stored in its memory. If a buffer overflow is then triggered, the data in these packets will be assigned a far larger memory space than required, causing other memory pointers to expose their contents. An attacker could exploit this by sending their malicious data via normal advertising packets before causing a buffer overflow with a malformed advertising packet. The malicious code stored in the initial packets could then be executed, or the exposed code could be leveraged to gain control of the affected device.
The second vulnerability (CVE-2018-7080) appears to be specific to the Aruba 300 series access points and their usage of the Over the Air firmware Download (OAD) feature, used to provide remote firmware updates. The feature uses hard-coded credentials and is intended to be disabled by default on commercial devices but appears to be enabled on 300 series devices. An attacker with access to the appropriate credentials could gain access to an affected device, replace the BLE micro-controller's firmware with their own version and take full control of the device.
For further information:
Remediation advice
Users and administrators are encouraged to apply the following patches immediately:Remediation steps
| Type | Step |
|---|---|
|
CVE Vulnerabilities
Last edited: 17 February 2020 12:38 pm