PT-2021-4302 · Ab32Vg1 · Ab32Vg1

Published

2021-09-07

·

Updated

2021-09-13

·

CVE-2021-31610

CVSS v2.0

6.1

Medium

VectorAV:A/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions AB32VG1 devices (affected versions not specified)
Description The Bluetooth Classic implementation does not properly handle the reception of continuous unsolicited LMP responses. This allows attackers in radio range to trigger a denial of service, either restarting or deadlocking the device, by flooding it with LMP AU rand data. The issue is also related to errors in resource release. An attacker can exploit this to cause the device to hang and restart.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Resource Release

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-04911
CVE-2021-31610

Affected Products

Ab32Vg1