PT-2021-4309 · Jbl+1 · Jbl Tune500Bt+1

Published

2021-09-07

·

Updated

2021-09-09

·

CVE-2021-28155

CVSS v2.0

6.1

Medium

VectorAV:A/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions JBL TUNE500BT devices (affected versions not specified) ESP32 series modules (affected versions not specified)
Description The issue is related to the Bluetooth Classic implementation, which does not properly handle certain data. This can allow an attacker to trigger a denial of service, shutting down a device by flooding it with LMP Feature Response data. The attacker must be within radio range to exploit this issue.
Recommendations For JBL TUNE500BT devices, restrict access to the device when not in use to minimize the risk of exploitation. For ESP32 series modules, avoid using the Bluetooth Classic implementation until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-04918
CVE-2021-28155

Affected Products

Esp32
Jbl Tune500Bt