Vulnerabilities
Vulnerable Software
Zh-Jieli:  >> Fw-Ac63 Bt Sdk  Security Vulnerabilities
The Bluetooth Classic implementation in the Zhuhai Jieli AC6366C_DEMO_V1.0 does not properly handle the reception of continuous unsolicited LMP responses, allowing attackers in radio range to trigger a denial of service (deadlock) of the device by flooding it with LMP_AU_Rand packets after paging procedure. User intervention is required to restart the device.
CVSS Score
6.5
EPSS Score
0.002
Published
2021-09-07
The Bluetooth Classic implementation in the Zhuhai Jieli AC6366C BT SDK through 0.9.1 does not properly handle the reception of truncated LMP_SCO_Link_Request packets while no other BT connections are active, allowing attackers in radio range to prevent new BT connections (disabling the AB5301A inquiry and page scan procedures) via a crafted LMP packet. The user needs to manually perform a power cycle (restart) of the device to restore BT connectivity.
CVSS Score
6.5
EPSS Score
0.001
Published
2021-09-07


Contact Us

Shodan ® - All rights reserved