CVE-2019-17517: Dialog-Semiconductor Software Development Kit
Medium severity, CVSS 5.7. EPSS: 0.6% chance of exploitation in the next 30 days.
The Bluetooth Low Energy implementation on Dialog Semiconductor SDK through 5.0.4 for DA14580/1/2/3 devices does not properly restrict the L2CAP payload length, allowing attackers in radio range to cause a buffer overflow via a crafted Link Layer packet.
Affected products
- Dialog-Semiconductor Software Development Kit: up to and including 5.0.4
Published 2020-02-10. Last modified 2026-06-17.