Cypress records
12 published records for vendor cypress.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 33.3%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')2
- CWE-787 Out-of-bounds Write2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-331 Insufficient Entropy1
- CWE-732 Incorrect Permission Assignment for Critical Resource1
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
12 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
35Monitor | CVE-2019-13916No exploit | An issue was discovered in Cypress (formerly Broadcom) WICED Studio 6.2 CYW20735B1 and CYW20819A1.cypress · wiced studio · CWE-787 | High8.8 | — | 1.2% | Apr 13, 2020 |
35Monitor | CVE-2018-19860No exploit | Broadcom firmware before summer 2014 on Nexus 5 BCM4335C0 2012-12-11, Raspberry Pi 3 BCM43438A1 2014-06-02, and unspecifed other devices doebroadcom · bcm4335c0 firmware · CWE-732 | High8.8 | — | 1.0% | Jun 7, 2019 |
34Monitor | CVE-2023-47415No exploit | Cypress Solutions CTM-200 v2.7.1.5600 and below was discovered to contain an OS command injection vulnerability via the cli_text parameter.cypress · ctm-200 firmware · CWE-78 | High7.5 | — | 13.8% | Mar 6, 2024 |
31Monitor | CVE-2019-18614No exploit | On the Cypress CYW20735 evaluation board, any data that exceeds 384 bytes is copied and causes an overflow.cypress · cyw20735 firmware · CWE-787 | High7.8 | — | 0.3% | Jun 16, 2020 |
30Monitor | CVE-2020-11957No exploit | The Bluetooth Low Energy implementation in Cypress PSoC Creator BLE 4.2 component versions before 3.64 generates a random number (Pairing Racypress · psoc 4.2 ble · CWE-331 | High7.5 | — | 0.4% | Jun 9, 2020 |
26Monitor | CVE-2019-16336No exploit | The Bluetooth Low Energy implementation in Cypress PSoC 4 BLE component 3.61 and earlier processes data channel frames with a payload lengthcypress · cyble-416045 · CWE-120 | Medium6.5 | — | 1.5% | Feb 12, 2020 |
26Monitor | CVE-2019-17061No exploit | The Bluetooth Low Energy (BLE) stack implementation on Cypress PSoC 4 through 3.62 devices does not properly restrict the BLE Link Layer heacypress · psoc 4 ble · CWE-120 | Medium6.5 | — | 0.9% | Feb 10, 2020 |
26Monitor | CVE-2021-34146No exploit | The Bluetooth Classic implementation in the Cypress CYW920735Q60EVB does not properly handle the reception of continuous unsolicited LMP rescypress · cyw920735q60evb-01 firmware | Medium6.5 | — | 0.6% | Sep 7, 2021 |
26Monitor | CVE-2021-34147No exploit | The Bluetooth Classic implementation in the Cypress WICED BT stack through 2.9.0 for CYW20735B1 does not properly handle the reception of a cypress · wireless internet connectivity for embedded devices | Medium6.5 | — | 0.6% | Sep 7, 2021 |
26Monitor | CVE-2021-34148No exploit | The Bluetooth Classic implementation in the Cypress WICED BT stack through 2.9.0 for CYW20735B1 devices does not properly handle the recepticypress · wireless internet connectivity for embedded devices | Medium6.5 | — | 0.6% | Sep 7, 2021 |
21Monitor | CVE-2021-34145No exploit | The Bluetooth Classic implementation in the Cypress WICED BT stack through 2.9.0 for CYW20735B1 devices does not properly handle the recepticypress · wireless internet connectivity for embedded devices | Medium5.3 | — | 0.5% | Sep 7, 2021 |
20Monitor | CVE-2007-5922No exploit | The modules/mdop.m in the Cypress 1.0k script for BitchX, as downloaded from a distribution site in November 2007, contains an externally inbitchx · bitchx · CWE-200 | Medium5.0 | — | 1.0% | Nov 9, 2007 |
- CVE-2019-1391635Monitor
An issue was discovered in Cypress (formerly Broadcom) WICED Studio 6.2 CYW20735B1 and CYW20819A1.
HighCVSS 8.8No exploitEPSS 1%cypress · wiced studioApr 13, 2020
- CVE-2018-1986035Monitor
Broadcom firmware before summer 2014 on Nexus 5 BCM4335C0 2012-12-11, Raspberry Pi 3 BCM43438A1 2014-06-02, and unspecifed other devices doe
HighCVSS 8.8No exploitEPSS 1%broadcom · bcm4335c0 firmwareJun 7, 2019
- CVE-2023-4741534Monitor
Cypress Solutions CTM-200 v2.7.1.5600 and below was discovered to contain an OS command injection vulnerability via the cli_text parameter.
HighCVSS 7.5No exploitEPSS 14%cypress · ctm-200 firmwareMar 6, 2024
- CVE-2019-1861431Monitor
On the Cypress CYW20735 evaluation board, any data that exceeds 384 bytes is copied and causes an overflow.
HighCVSS 7.8No exploitEPSS 0%cypress · cyw20735 firmwareJun 16, 2020
- CVE-2020-1195730Monitor
The Bluetooth Low Energy implementation in Cypress PSoC Creator BLE 4.2 component versions before 3.64 generates a random number (Pairing Ra
HighCVSS 7.5No exploitEPSS 0%cypress · psoc 4.2 bleJun 9, 2020
- CVE-2019-1633626Monitor
The Bluetooth Low Energy implementation in Cypress PSoC 4 BLE component 3.61 and earlier processes data channel frames with a payload length
MediumCVSS 6.5No exploitEPSS 1%cypress · cyble-416045Feb 12, 2020
- CVE-2019-1706126Monitor
The Bluetooth Low Energy (BLE) stack implementation on Cypress PSoC 4 through 3.62 devices does not properly restrict the BLE Link Layer hea
MediumCVSS 6.5No exploitEPSS 1%cypress · psoc 4 bleFeb 10, 2020
- CVE-2021-3414626Monitor
The Bluetooth Classic implementation in the Cypress CYW920735Q60EVB does not properly handle the reception of continuous unsolicited LMP res
MediumCVSS 6.5No exploitEPSS 1%cypress · cyw920735q60evb-01 firmwareSep 7, 2021
- CVE-2021-3414726Monitor
The Bluetooth Classic implementation in the Cypress WICED BT stack through 2.9.0 for CYW20735B1 does not properly handle the reception of a
MediumCVSS 6.5No exploitEPSS 1%cypress · wireless internet connectivity for embedded devicesSep 7, 2021
- CVE-2021-3414826Monitor
The Bluetooth Classic implementation in the Cypress WICED BT stack through 2.9.0 for CYW20735B1 devices does not properly handle the recepti
MediumCVSS 6.5No exploitEPSS 1%cypress · wireless internet connectivity for embedded devicesSep 7, 2021
- CVE-2021-3414521Monitor
The Bluetooth Classic implementation in the Cypress WICED BT stack through 2.9.0 for CYW20735B1 devices does not properly handle the recepti
MediumCVSS 5.3No exploitEPSS 1%cypress · wireless internet connectivity for embedded devicesSep 7, 2021
- CVE-2007-592220Monitor
The modules/mdop.m in the Cypress 1.0k script for BitchX, as downloaded from a distribution site in November 2007, contains an externally in
MediumCVSS 5.0No exploitEPSS 1%bitchx · bitchxNov 9, 2007