PT-2021-4298 · Texas Instruments · Cc256X

Published

2021-09-07

·

Updated

2021-09-09

·

CVE-2021-34149

CVSS v2.0

3.3

Low

VectorAV:A/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Texas Instruments CC256XCQFN-EM (affected versions not specified)
Description The Bluetooth Classic implementation does not properly handle the reception of continuous LMP AU Rand packets, allowing attackers in radio range to trigger a denial of service (deadlock) of the device by flooding it with LMP AU Rand packets after the paging procedure. The issue is also related to buffer overflow errors in dynamic memory.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-04907
CVE-2021-34149

Affected Products

Cc256X