nordicsemi CVE Vulnerabilities & CVE List (6)

Products (CPE): — CVEs: 6

nordicsemi vulnerability overview

Aggregates CVE and security vulnerability intelligence across all nordicsemi-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Historical issues mainly involve vendor risk memory corruption, vendor risk buffer overflow, and vendor risk denial of service and related problems; some flaws may lead to vendor impact memory corruption.

Vulnerability distribution trend (last 24 months)

Showing 16 of 6 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2022-40480 Nordic Semiconductor, Microchip Technology NRF5340-DK DT100112 was discovered to contain an issue which allows attackers to cause a Denial of Service (DoS) via a crafted ConReq packet. [email protected] 6.5 0.30% 2023-02-07 2026-06-17
CVE-2022-35624 In Nordic nRF5 SDK for Mesh 5.0, a heap overflow vulnerability can be triggered by sending a series of segmented packets with SegO > SegN [email protected] 8.2 0.86% 2022-08-15 2026-06-17
CVE-2022-35623 In Nordic nRF5 SDK for Mesh 5.0, a heap overflow vulnerability can be triggered by sending a series of segmented control packets and access packets with the same SeqAuth [email protected] 8.2 0.86% 2022-08-15 2026-06-17
CVE-2020-27211 Nordic Semiconductor nRF52840 devices through 2020-10-19 have improper protection against physical side channels. The flash read-out protection (APPROTECT) can be bypassed by injecting a fault during the boot phase. [email protected] 5.7 0.28% 2021-05-21 2026-06-16
CVE-2021-29415 The elliptic curve cryptography (ECC) hardware accelerator, part of the ARM® TrustZone® CryptoCell 310, contained in the NordicSemiconductor nRF52840 through 2021-03-29 has a non-constant time ECDSA implemenation. This allows an adversary to recover the private ECC key used during an ECDSA operation. [email protected] 5.5 0.27% 2021-05-21 2026-06-16
CVE-2020-15509 Nordic Semiconductor Android BLE Library through 2.2.1 and DFU Library through 1.10.4 for Android (as used by nRF Connect and other applications) can engage in unencrypted communication while showing the user that the communication is purportedly encrypted. The problem is in bond creation (e.g., internalCreateBond in BleManagerHandler). [email protected] 6.5 0.54% 2020-07-07 2026-06-16
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence