PT-2021-4357 · Ats2819+1 · Ats2819+1

Published

2021-09-07

·

Updated

2022-07-12

·

CVE-2021-31786

CVSS v2.0

6.1

Medium

VectorAV:A/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Actions ATS2815 and ATS2819 devices (affected versions not specified)
Description The issue arises from insufficient input validation in the Bluetooth Classic firmware of the devices. This can be exploited by a remote attacker to cause a denial of service through a crafted LMP packet. Specifically, the Bluetooth Classic Audio implementation does not properly handle a connection attempt from a host with the same BDAddress as the current connected BT host, allowing attackers to trigger a disconnection and deadlock of the device by connecting with a forged BDAddress that matches the original connected host.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Locking

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-04986
CVE-2021-31786

Affected Products

Ats2815
Ats2819