<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://devzone.nordicsemi.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>A suite of vulnerabilities related to devices using Low Energy (BLE) wireless communications protocol</title><link>https://devzone.nordicsemi.com/f/nordic-q-a/59134/a-suite-of-vulnerabilities-related-to-devices-using-low-energy-ble-wireless-communications-protocol</link><description>Good afternoon, Today we had a question about the certification of our product related to the reliability of communication. We received a letter of the following content: 
 
 I would like to receive your comments regarding the detected vulnerabilities</description><dc:language>en-US</dc:language><generator>Telligent Community 13</generator><lastBuildDate>Mon, 23 Mar 2020 08:45:03 GMT</lastBuildDate><atom:link rel="self" type="application/rss+xml" href="https://devzone.nordicsemi.com/f/nordic-q-a/59134/a-suite-of-vulnerabilities-related-to-devices-using-low-energy-ble-wireless-communications-protocol" /><item><title>RE: A suite of vulnerabilities related to devices using Low Energy (BLE) wireless communications protocol</title><link>https://devzone.nordicsemi.com/thread/241045?ContentTypeID=1</link><pubDate>Mon, 23 Mar 2020 08:45:03 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:491d8912-52f6-4aea-bd77-82195a4d0794</guid><dc:creator>CheMax</dc:creator><description>&lt;p&gt;Hi,&amp;nbsp;below the contents of the letter:&lt;/p&gt;
&lt;p&gt;&lt;pre class="ui-code" data-mode="text"&gt;Hi Maxim,

All vulnerabilities have registered CVEs and are documented here:
https://asset-group.github.io/disclosures/sweyntooth/sweyntooth.pdf

All CVEs identify the hardware and software platforms affected.  
Nordic is not documented as an affected platform.
The fact that our devices and software are unaffected is evidenced in the fact 
we are not identified in the CVEs.  We do not need to issue an official statement to verify this, 
it can be independently verified by anyone as the CVE database is public. 

MACIEJ MICHNA | Regional Sales Manager
M +48 600 439 203 | Krak&amp;#243;w, Poland
nordicsemi.com | devzone.nordicsemi.com 
&lt;/pre&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: A suite of vulnerabilities related to devices using Low Energy (BLE) wireless communications protocol</title><link>https://devzone.nordicsemi.com/thread/241021?ContentTypeID=1</link><pubDate>Mon, 23 Mar 2020 03:22:19 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:b56b6cda-faff-4e22-bc72-4acda014925c</guid><dc:creator>had23j</dc:creator><description>&lt;p&gt;&lt;a href="https://devzone.nordicsemi.com/members/chemax"&gt;CheMax&lt;/a&gt; were you able to get a document to prove that&amp;nbsp;&lt;span&gt;nRF52 BLE stacks are&amp;nbsp;&lt;/span&gt;&lt;strong&gt;not&amp;nbsp;&lt;/strong&gt;&lt;span&gt;affected by&amp;nbsp;&lt;/span&gt;&lt;strong&gt;any&amp;nbsp;&lt;/strong&gt;&lt;span&gt;of the sweyntooth&amp;nbsp;vulnerabilities ?&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: A suite of vulnerabilities related to devices using Low Energy (BLE) wireless communications protocol</title><link>https://devzone.nordicsemi.com/thread/240019?ContentTypeID=1</link><pubDate>Mon, 16 Mar 2020 13:17:21 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:7210ef7f-3c26-4bd6-972e-dc359f925d85</guid><dc:creator>CheMax</dc:creator><description>&lt;p&gt;Ok, thanks.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: A suite of vulnerabilities related to devices using Low Energy (BLE) wireless communications protocol</title><link>https://devzone.nordicsemi.com/thread/240010?ContentTypeID=1</link><pubDate>Mon, 16 Mar 2020 13:03:32 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:3bfb9406-13ea-4a9a-a840-4e120f824e85</guid><dc:creator>Simonr</dc:creator><description>&lt;p&gt;Hi&lt;/p&gt;
&lt;p&gt;Please contact your local RSM for more details on what tests we did to confirm that we are not affected by these vulnerabilities.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Best regards,&lt;/p&gt;
&lt;p&gt;Simon&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: A suite of vulnerabilities related to devices using Low Energy (BLE) wireless communications protocol</title><link>https://devzone.nordicsemi.com/thread/239958?ContentTypeID=1</link><pubDate>Mon, 16 Mar 2020 10:58:44 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:e1dcea9e-1fe8-4e67-98af-d873816113ed</guid><dc:creator>CheMax</dc:creator><description>&lt;p&gt;Hi Simon,&lt;/p&gt;
&lt;p&gt;Thanks for very fast answer.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;It is wonderful that there are no vulnerabilities. In the article, as I understand it, not all manufacturers are listed, for example, the same Silabs are also absent.&lt;br /&gt;How can you confirm your assurances to the auditors if they have questions?&lt;br /&gt;Unfortunately they may not believe a word :(&lt;/p&gt;
&lt;p&gt;Best regards&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: A suite of vulnerabilities related to devices using Low Energy (BLE) wireless communications protocol</title><link>https://devzone.nordicsemi.com/thread/239954?ContentTypeID=1</link><pubDate>Mon, 16 Mar 2020 10:47:24 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:2eae7ce2-7289-46e8-809b-d0ea9e236831</guid><dc:creator>Simonr</dc:creator><description>&lt;p&gt;Hi Max&lt;/p&gt;
&lt;p&gt;We&amp;#39;ve tested these vulnerabilities up against our BLE devices, and we&amp;#39;ve found that our integration and system tests have been testing all the sequences of transactions that have been used to explore the vulnerabilities in the BLE chips. These tests have been in our system for years. This means that&amp;nbsp;&lt;strong&gt;all&amp;nbsp;&lt;/strong&gt;versions of our nRF51 and nRF52 BLE stacks are&amp;nbsp;&lt;strong&gt;not&amp;nbsp;&lt;/strong&gt;affected by&amp;nbsp;&lt;strong&gt;any&amp;nbsp;&lt;/strong&gt;of these vulnerabilities.&amp;nbsp;&lt;strong&gt;&lt;/strong&gt;As you can see in the article in question, Nordic Semiconductor is not mentioned as one of the affected devices.&lt;/p&gt;
&lt;p&gt;Best regards,&lt;/p&gt;
&lt;p&gt;Simon&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>