CVE-2021-31612
The Bluetooth Classic implementation on Zhuhai Jieli AC690X devices does not properly handle the reception of an oversized LMP packet greater than 17 bytes during the LMP auto rate procedure, allowing attackers in radio range to trigger a deadlock via a…
Does this matter?
Lower severity and a low EPSS score (0.53%). Track it; it rarely justifies an emergency change on its own.
Description
The Bluetooth Classic implementation on Zhuhai Jieli AC690X devices does not properly handle the reception of an oversized LMP packet greater than 17 bytes during the LMP auto rate procedure, allowing attackers in radio range to trigger a deadlock via a crafted LMP packet.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 0.53% probability · 43th percentile
- CISA KEV
- Not listed
- Affected
- zh-jieli/ac6901 firmware · zh-jieli/ac690n firmware · zh-jieli/ac692n firmware · zh-jieli/ac6902 firmware · zh-jieli/ac6903 firmware · zh-jieli/ac6905 firmware · zh-jieli/ac6904 firmware · zh-jieli/ac6907 firmware · zh-jieli/ac6908 firmware · zh-jieli/ac6997 firmware · zh-jieli/ac6998 firmware · zh-jieli/ac6999 firmware
- Source
- cve@mitre.org
References
- http://www.zh-jieli.com/product/68-cn.htmlProduct, Vendor Advisory
- https://dl.packetstormsecurity.net/papers/general/braktooth.pdfBroken Link
- https://launchstudio.bluetooth.com/ListingDetails/19746Third Party Advisory
- http://www.zh-jieli.com/product/68-cn.htmlProduct, Vendor Advisory
- https://dl.packetstormsecurity.net/papers/general/braktooth.pdfBroken Link
- https://launchstudio.bluetooth.com/ListingDetails/19746Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.