MEDIUM · 6.5

CVE-2021-34143

The Bluetooth Classic implementation in the Zhuhai Jieli AC6366C_DEMO_V1.0 does not properly handle the reception of continuous unsolicited LMP responses, allowing attackers in radio range to trigger ...

Vulnerability Description

The Bluetooth Classic implementation in the Zhuhai Jieli AC6366C_DEMO_V1.0 does not properly handle the reception of continuous unsolicited LMP responses, allowing attackers in radio range to trigger a denial of service (deadlock) of the device by flooding it with LMP_AU_Rand packets after paging procedure. User intervention is required to restart the device.

CVSS Score

6.5

MEDIUM

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
Zh-JieliFw-Ac63 Bt Sdk1.0.0
Zh-JieliAc6936-
Zh-JieliAc6951-
Zh-JieliAc6952-
Zh-JieliAc6954-
Zh-JieliAc6955-
Zh-JieliAc6956-
Zh-JieliAc6963-
Zh-JieliAc6965-
Zh-JieliAc6966-
Zh-JieliAc6969-
Zh-JieliAc6973-
Zh-JieliAc6976-
Zh-JieliAc6983-
Zh-JieliAc6986-

References

FAQ

What is CVE-2021-34143?

CVE-2021-34143 is a vulnerability with a CVSS score of 6.5 (MEDIUM). The Bluetooth Classic implementation in the Zhuhai Jieli AC6366C_DEMO_V1.0 does not properly handle the reception of continuous unsolicited LMP responses, allowing attackers in radio range to trigger ...

How severe is CVE-2021-34143?

CVE-2021-34143 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-34143?

Check the references section above for vendor advisories and patch information. Affected products include: Zh-Jieli Fw-Ac63 Bt Sdk, Zh-Jieli Ac6936, Zh-Jieli Ac6951, Zh-Jieli Ac6952, Zh-Jieli Ac6954.