Buffer overflow in BLE-STACK - CVE-2018-16986
Published: November 1, 2018 / Updated: November 2, 2018
Vulnerability details
The vulnerability allows a physical attacker to execute arbitrary code on the target system.
The weakness exists due to boundary error when handling malicious input if BLE is turned on and the device is actively scanning. A physical attacker who is in range of the targeted device can send specially crafted packets containing malformed BLE frames, trigger memory corruption and execute arbitrary code. The attacker can also install a backdoor on the chip and then gain complete control of the system. In the case of access points, the attacker can use the compromised AP to spread to other devices on the network, even if segmentation is in place.
The vulnerability has been dubbed as "BLEEDINGBIT".
Affected software
CC2640
CC2640R2
Cisco 1540 Aironet Series Outdoor Access Points
Cisco 1800i Aironet Access Points
Cisco 1810 Aironet Access Points
Cisco 1815i Aironet Access Points
Cisco 1815m Aironet Access Points
Cisco 1815w Aironet Access Points
Cisco 4800 Aironet Access Points
Meraki MR30H AP
Meraki MR33 AP
Meraki MR42E AP
Meraki MR53E AP
Meraki MR74
How to mitigate CVE-2018-16986
Cisco 1540 Aironet Series Outdoor Access Points - update to 8.8.100.0
Cisco 1800i Aironet Access Points - update to 8.8.100.0
Cisco 1810 Aironet Access Points - update to 8.8.100.0
Cisco 1815i Aironet Access Points - update to 8.8.100.0
Cisco 1815m Aironet Access Points - update to 8.8.100.0
Cisco 1815w Aironet Access Points - update to 8.8.100.0
Cisco 4800 Aironet Access Points - update to 8.8.100.0
Meraki MR30H AP - update to MR 25.13
Meraki MR33 AP - update to MR 25.13
Meraki MR42E AP - update to MR 25.13
Meraki MR53E AP - update to MR 25.13
Meraki MR74 - update to MR 25.13