PT-2021-4309 · Jbl+1 · Jbl Tune500Bt+1
Published
2021-09-07
·
Updated
2021-09-09
·
CVE-2021-28155
CVSS v2.0
6.1
Medium
| Vector | AV:A/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
JBL TUNE500BT devices (affected versions not specified)
ESP32 series modules (affected versions not specified)
Description
The issue is related to the Bluetooth Classic implementation, which does not properly handle certain data. This can allow an attacker to trigger a denial of service, shutting down a device by flooding it with LMP Feature Response data. The attacker must be within radio range to exploit this issue.
Recommendations
For JBL TUNE500BT devices, restrict access to the device when not in use to minimize the risk of exploitation.
For ESP32 series modules, avoid using the Bluetooth Classic implementation until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Esp32
Jbl Tune500Bt