6.5

CVE-2021-34143

The Bluetooth Classic implementation in the Zhuhai Jieli AC6366C_DEMO_V1.0 does not properly handle the reception of continuous unsolicited LMP responses, allowing attackers in radio range to trigger a denial of service (deadlock) of the device by flooding it with LMP_AU_Rand packets after paging procedure. User intervention is required to restart the device.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zh-jieli ≫ Fw-ac63 Bt Sdk Version 1.0.0
   Zh-jieli ≫ Ac6936 Version -
   Zh-jieli ≫ Ac6951 Version -
   Zh-jieli ≫ Ac6952 Version -
   Zh-jieli ≫ Ac6954 Version -
   Zh-jieli ≫ Ac6955 Version -
   Zh-jieli ≫ Ac6956 Version -
   Zh-jieli ≫ Ac6963 Version -
   Zh-jieli ≫ Ac6965 Version -
   Zh-jieli ≫ Ac6966 Version -
   Zh-jieli ≫ Ac6969 Version -
   Zh-jieli ≫ Ac6973 Version -
   Zh-jieli ≫ Ac6976 Version -
   Zh-jieli ≫ Ac6983 Version -
   Zh-jieli ≫ Ac6986 Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.75% 0.502
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.5 2.8 3.6
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
NIST 6.1 6.5 6.9
AV:A/AC:L/Au:N/C:N/I:N/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://dl.packetstormsecurity.net/papers/general/braktooth.pdf
Broken Link
https://github.com/Jieli-Tech/fw-AC63_BT_SDK
Third Party Advisory
https://launchstudio.bluetooth.com/ListingDetails/91371
Third Party Advisory