The vendor explicitly identifies these products as affected by this CVE.
- Schneider Electric Harmony® eXLhoist base stations V04.00.02.00 and prior
- Summary
- The Bluetooth Low Energy peripheral implementation on Texas Instruments SIMPLELINKCC2640R2-SDK through 3.30.00.20 and BLE-STACK through 1.5.0 before Q4 2019 for CC2640R2 and CC2540/1 devices does not properly restrict the advertisement connection request packet on reception, allowing attackers in radio range to cause a denial of service (crash) via a crafted packet.
- Remediation
- This vulnerability is fixed in base station V04.00.03.00 and is available for download below: https://www.se.com/fr/fr/download/document/eXLhoistFirmwareV4060/
