A group of security researchers uncovered a 12 Bluetooth based vulnerabilities dubbed “SweynTooth” in BLE software development kits of seven major system-on-a-chip (SoC) vendors.
BLE ( Bluetooth Low Energy ) a technology developed for wireless communication with a set of many standardized protocols that provide remote connectivity and also specifically handles the battery life of the device different power consumption and usage capabilities.
We have recently reported another critical Bluetooth vulnerability discovered in the Android Bluetooth system that allows remote attackers to silently execute arbitrary code remotely and take the complete device control.
Also, SweynTooth vulnerabilities affected various IoT products in appliances such as smart-homes, wearables and environmental tracking or sensing, medical and logistics products.
Vulnerable BLE SDKs sold by seven vendors of the following:
There are 3 types of major SweynTooth flaw identified in this research and each vulnerability impact the devices in different ways,
Six Bluetooth vulnerabilities are addressed that lead to crash a device once the attacker triggers the vulnerabilities due to some incorrect code behavior or memory corruption.
This vulnerability affected the vendors including Cypress, NXP, Dialog Semiconductors, Texas Instruments, Microchip, Telink Semiconductor.
There are 3 vulnerabilities related to Deadlock type that affect the availability of the BLE connection without causing a hard fault or memory corruption.
Researchers explain that they usually occurred due to some improper synchronization between user code and the SDK firmware distributed by the SoC vendor, leaving the user code being stuck at some point.
There are 3 Vendors affected by these vulnerabilities: Cypress, NXP, STMicroelectronics.
Security bypass type Bluetooth vulnerability in SweynTooth consider as a “Critical” one and the vulnerability allows attackers in radio range to bypass the latest secure pairing mode of BLE.
Successfully exploit this vulnerability allow attack to perform an arbitrary read or write access to the device’s functions remotely.
Attackers also perform smart luggage lock that can be remotely locked or unlocked through a smartphone app.
This Zero LTK Installation security bypass Bluetooth vulnerability ( CVE-2019-19194 ) affected only Zero LTK Installation.
You can also read the detailed and in-depth technical details here .
feshop fullz fresh cc for carding