Vulnerability Details CVE-2021-31786
The Bluetooth Classic Audio implementation on Actions ATS2815 and ATS2819 devices does not properly handle a connection attempt from a host with the same BDAddress as the current connected BT host, allowing attackers to trigger a disconnection and deadlock of the device by connecting with a forged BDAddress that matches the original connected host.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 29.6%
CVSS Severity
CVSS v3 Score 6.5
CVSS v2 Score 6.1
Products affected by CVE-2021-31786
-
cpe:2.3:h:actions-semi:ats2815:-
-
cpe:2.3:h:actions-semi:ats2819:-
-
cpe:2.3:h:actions-semi:ats2819p:-
-
cpe:2.3:h:actions-semi:ats2819s:-
-
cpe:2.3:h:actions-semi:ats2819t:-
-
cpe:2.3:o:actions-semi:ats2815_firmware:-
-
cpe:2.3:o:actions-semi:ats2819_firmware:-
-
cpe:2.3:o:actions-semi:ats2819p_firmware:-
-
cpe:2.3:o:actions-semi:ats2819s_firmware:-
-
cpe:2.3:o:actions-semi:ats2819t_firmware:-