PT-2021-4299 · Zhuhai Jieli · Ac692X+1
Published
2021-09-07
·
Updated
2021-09-09
·
CVE-2021-31613
CVSS v2.0
3.3
Low
| Vector | AV:A/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Zhuhai Jieli AC690X and AC692X devices (affected versions not specified)
Description
The Bluetooth Classic implementation does not properly handle the reception of a truncated LMP packet during the LMP auto rate procedure. This allows attackers in radio range to immediately crash and restart a device via a crafted LMP packet. The issue exists due to insufficient input validation in the Bluetooth Classic implementation.
Recommendations
For Zhuhai Jieli AC690X and AC692X devices, consider disabling Bluetooth functionality until a patch is available to prevent exploitation.
Restrict access to devices to minimize the risk of exploitation by attackers in radio range.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ac690X
Ac692X