5.3

CVE-2021-21966

Exploit

An information disclosure vulnerability exists in the HTTP Server /ping.html functionality of Texas Instruments CC3200 SimpleLink Solution NWP 2.9.0.0. A specially-crafted HTTP request can lead to an uninitialized read. An attacker can send an HTTP request to trigger this vulnerability.

Data is provided by the National Vulnerability Database (NVD)
TiSimplelink Cc32xx Software Development Kit Version < 5.30.00.08
   TiCc3120 Version-
   TiCc3130 Version-
   TiCc3135 Version-
   TiCc3220r Version-
   TiCc3220s Version-
   TiCc3220sf Version-
   TiCc3230s Version-
   TiCc3230sf Version-
   TiCc3235s Version-
   TiCc3235sf Version-
TiCc3100 Firmware Version < 1.0.1.15-2.15.0.1
   TiCc3100 Version-
TiCc3200 Firmware Version < 1.0.1.15-2.15.0.1
   TiCc3200 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 2.02% 0.827
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
talos-cna@cisco.com 5.3 3.9 1.4
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CWE-457 Use of Uninitialized Variable

The code uses a variable that has not been initialized, leading to unpredictable or unintended results.

CWE-908 Use of Uninitialized Resource

The product uses or accesses a resource that has not been initialized.