Executive brief
Nordic Semiconductor's Bluetooth-enabled devices implement a Continuous Glucose Monitoring Service used in medical and fitness devices. A buffer overflow in the RACP (Record Access Control Point) write handler allows an authenticated attacker to overwrite adjacent memory, potentially causing device malfunction or enabling further exploitation depending on the specific device's memory layout.
Technical details
A buffer overflow vulnerability exists in the Bluetooth CGMS Record Access Control Point (RACP) write handler, where a 20-byte static buffer can be overflowed into adjacent BSS (Block Started by Symbol) memory. The vulnerability requires an authenticated BLE peer within wireless range and involves writing malformed data to the RACP characteristic. The impact is dependent on the linker-assigned memory layout of the specific firmware build, making exploitation unpredictable but potentially enabling code execution or denial of service. The reported severity and lack of CVSS scoring suggest limited immediate exploitability or impact assessments available at disclosure.
Affected products
- Nordic Semiconductor Bluetooth CGMS implementation
Timeline
- 2026-09-07: disclosed