6.5
CVE-2021-31785
- EPSS 0.1%
- Published 07.09.2021 07:15:07
- Last modified 21.11.2024 06:06:13
- Source cve@mitre.org
- Teams watchlist Login
- Open Login
The Bluetooth Classic implementation on Actions ATS2815 and ATS2819 chipsets does not properly handle the reception of multiple LMP_host_connection_req packets, allowing attackers in radio range to trigger a denial of service (deadlock) of the device via crafted LMP packets. Manual user intervention is required to restart the device and restore Bluetooth communication.
Data is provided by the National Vulnerability Database (NVD)
Actions-semi ≫ Ats2819p Firmware Version-
Actions-semi ≫ Ats2815 Firmware Version-
Actions-semi ≫ Ats2819 Firmware Version-
Actions-semi ≫ Ats2819s Firmware Version-
Actions-semi ≫ Ats2819t Firmware Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.1% | 0.254 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
nvd@nist.gov | 6.1 | 6.5 | 6.9 |
AV:A/AC:L/Au:N/C:N/I:N/A:C
|
CWE-667 Improper Locking
The product does not properly acquire or release a lock on a resource, leading to unexpected resource state changes and behaviors.