Vulnerability Details CVE-2021-34143
The Bluetooth Classic implementation in the Zhuhai Jieli AC6366C_DEMO_V1.0 does not properly handle the reception of continuous unsolicited LMP responses, allowing attackers in radio range to trigger a denial of service (deadlock) of the device by flooding it with LMP_AU_Rand packets after paging procedure. User intervention is required to restart the device.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 47.3%
CVSS Severity
CVSS v3 Score 6.5
CVSS v2 Score 6.1
Products affected by CVE-2021-34143
-
cpe:2.3:h:zh-jieli:ac6936:-
-
cpe:2.3:h:zh-jieli:ac6951:-
-
cpe:2.3:h:zh-jieli:ac6952:-
-
cpe:2.3:h:zh-jieli:ac6954:-
-
cpe:2.3:h:zh-jieli:ac6955:-
-
cpe:2.3:h:zh-jieli:ac6956:-
-
cpe:2.3:h:zh-jieli:ac6963:-
-
cpe:2.3:h:zh-jieli:ac6965:-
-
cpe:2.3:h:zh-jieli:ac6966:-
-
cpe:2.3:h:zh-jieli:ac6969:-
-
cpe:2.3:h:zh-jieli:ac6973:-
-
cpe:2.3:h:zh-jieli:ac6976:-
-
cpe:2.3:h:zh-jieli:ac6983:-
-
cpe:2.3:h:zh-jieli:ac6986:-
-
cpe:2.3:o:zh-jieli:fw-ac63_bt_sdk:1.0.0