Skip to main content

BLEEDINGBIT Bluetooth Vulnerabilities

Security researchers have discovered two vulnerabilities, collectively known as BLEEDINGBIT, in Texas Instruments Bluetooth Low Energy (BLE) micro-controllers used in wireless access points manufactured by Aruba and Cisco.
Report a cyber attack: call 0300 303 5222 or email [email protected]

This content has been archived

This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk

Summary

Security researchers have discovered two vulnerabilities, collectively known as BLEEDINGBIT, in Texas Instruments Bluetooth Low Energy (BLE) micro-controllers used in wireless access points manufactured by Aruba and Cisco.

Affected platforms

The following platforms are known to be affected:

TI Wireless MCUs

Affected Texas Instruments products:

  • TI Wireless MCUs - CC1350, CC2540, CC2541, CC2640, CC2640R2, CC2640R2F, CC2642R and CC2650
  • BLE-STACK software suite - Version 2.2.1 or earlier

Affected Aruba products:

  • Aruba access points - AP203RP, AP203RAP, AP-3xx and IAP-3xx series
  • ArubaOS - Versions:
    • 6.4.4.x prior to 6.4.4.20
    • 6.5.3.x prior to 6.5.3.9
    • 6.5.4.x prior to 6.5.4.9
    • 8.x prior to 8.2.2.2
    • 8.3.x prior to 8.3.0.4

Affected Cisco products:

  • Cisco Aironet access points - 1800i, 1810, 1815i, 1815m, 1815w and 4800 series
  • Cisco Aironet outdoor access points - 1540 series
  • Meraki access points - MR30H, MR33, MR42E, MR53E and MR74 series

Threat details

The researchers claim that the vulnerabilities could be exploited to gain control of an affected device.

The first vulnerability (CVE-2018-16986) lies in how the affected micro-controllers handle specialised BLE packets known as advertising packets. When advertising packets are sent to an affected micro-controller they are stored in its memory. If a buffer overflow is then triggered, the data in these packets will be assigned a far larger memory space than required, causing other memory pointers to expose their contents. An attacker could exploit this by sending their malicious data via normal advertising packets before causing a buffer overflow with a malformed advertising packet. The malicious code stored in the initial packets could then be executed, or the exposed code could be leveraged to gain control of the affected device.

The second vulnerability (CVE-2018-7080) appears to be specific to the Aruba 300 series access points and their usage of the Over the Air firmware Download (OAD) feature, used to provide remote firmware updates. The feature uses hard-coded credentials and is intended to be disabled by default on commercial devices but appears to be enabled on 300 series devices. An attacker with access to the appropriate credentials could gain access to an affected device, replace the BLE micro-controller's firmware with their own version and take full control of the device.

For further information:


Remediation advice

Users and administrators are encouraged to apply the following patches immediately:

Remediation steps

Type Step


Last edited: 17 February 2020 12:38 pm