CVE-2021-31612
Estado: ModificadaMedia (6.5)—
The Bluetooth Classic implementation on Zhuhai Jieli AC690X devices does not properly handle the reception of an oversized LMP packet greater than 17 bytes during the LMP auto rate procedure, allowing attackers in radio range to trigger a deadlock via a crafted LMP packet.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Puntuación base: 6.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.53%
- Percentil entre todas las CVEs puntuadas: 43
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (12)
Zh-jieli — Ac6901 FirmwareZh-jieli — Ac6902 FirmwareZh-jieli — Ac6903 FirmwareZh-jieli — Ac6904 FirmwareZh-jieli — Ac6905 FirmwareZh-jieli — Ac6907 FirmwareZh-jieli — Ac6908 FirmwareZh-jieli — Ac690n FirmwareZh-jieli — Ac692n FirmwareZh-jieli — Ac6997 FirmwareZh-jieli — Ac6998 FirmwareZh-jieli — Ac6999 Firmware
CWE
- NVD-CWE-noinfo
Referencias
- http://www.zh-jieli.com/product/68-cn.html
- https://dl.packetstormsecurity.net/papers/general/braktooth.pdf
- https://launchstudio.bluetooth.com/ListingDetails/19746
- http://www.zh-jieli.com/product/68-cn.html
- https://dl.packetstormsecurity.net/papers/general/braktooth.pdf
- https://launchstudio.bluetooth.com/ListingDetails/19746
JSON original (NVD)
Mostrar
{
"id": "CVE-2021-31612",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 6.1,
"accessVector": "ADJACENT_NETWORK",
"vectorString": "AV:A/AC:L/Au:N/C:N/I:N/A:C",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 6.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 6.5,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 6.5,
"attackVector": "ADJACENT_NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2021-09-07T07:15:07.093",
"references": [
{
"url": "http://www.zh-jieli.com/product/68-cn.html",
"tags": [
"Product",
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://dl.packetstormsecurity.net/papers/general/braktooth.pdf",
"tags": [
"Broken Link"
],
"source": "cve@mitre.org"
},
{
"url": "https://launchstudio.bluetooth.com/ListingDetails/19746",
"tags": [
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.zh-jieli.com/product/68-cn.html",
"tags": [
"Product",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://dl.packetstormsecurity.net/papers/general/braktooth.pdf",
"tags": [
"Broken Link"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://launchstudio.bluetooth.com/ListingDetails/19746",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-noinfo"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The Bluetooth Classic implementation on Zhuhai Jieli AC690X devices does not properly handle the reception of an oversized LMP packet greater than 17 bytes during the LMP auto rate procedure, allowing attackers in radio range to trigger a deadlock via a crafted LMP packet."
},
{
"lang": "es",
"value": "Una implementación de Bluetooth Classic en los dispositivos Zhuhai Jieli AC690X, no maneja apropiadamente la recepción de un paquete LMP de gran tamaño, superior a 17 bytes, durante el procedimiento de auto calificación de LMP, permitiendo a atacantes en el rango de radio desencadenar un bloqueo por medio de un paquete LMP diseñado"
}
],
"lastModified": "2026-06-17T03:52:04.840",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:zh-jieli:ac6901_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A68BB39A-4A9C-4B57-9D29-12601FCFC763"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:zh-jieli:ac6901:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "06EBB244-F958-45C8-84B5-DFB3BA3E9449"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:zh-jieli:ac690n_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "78A24F18-DFE9-44B7-990A-D15F7440DB91"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:zh-jieli:ac690n:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "737F0352-0A9E-4242-B595-78C47C6655D7"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:zh-jieli:ac692n_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "00D94121-902F-4C9A-8BE8-D7B1A9910955"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:zh-jieli:ac692n:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "20A1E4AC-5F0C-4FBD-99ED-1EE81AC44A67"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:zh-jieli:ac6902_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4DA40F06-EAA2-4DD5-B223-F8A024611B93"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:zh-jieli:ac6902:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "9EED7E82-F385-4BF4-92C3-F1D87D4B27A0"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:zh-jieli:ac6903_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DA6F3C19-43E8-4917-B8D2-FE7D9DB06DB9"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:zh-jieli:ac6903:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "BB8D175B-C001-4978-822E-6F50BB0EC85E"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:zh-jieli:ac6905_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4A3465E0-3ABB-4F92-B1E2-177324FAAE92"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:zh-jieli:ac6905:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "08FB9CC5-15DF-485B-9D21-352E5262ADCA"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:zh-jieli:ac6904_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "64C5116C-D942-4308-B203-316B44FBE4A8"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:zh-jieli:ac6904:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "75974822-5B9D-4A62-8064-3256F512A759"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:zh-jieli:ac6907_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6F7FA9D5-7998-408E-B1C6-EBB001854296"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:zh-jieli:ac6907:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "B6F32791-2597-4EB8-B456-3E7BAD998EAF"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:zh-jieli:ac6908_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "211932B6-F00D-4D7B-A168-7EA747CCB921"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:zh-jieli:ac6908:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "E5D7C217-4F8D-46F9-AA17-BE8C53A7EEF4"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:zh-jieli:ac6997_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "20483D02-4362-4BB9-8563-EA8AC058A4CD"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:zh-jieli:ac6997:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "5AA70E93-3D24-4898-B480-280957F5AB80"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:zh-jieli:ac6998_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "434115EC-714C-4110-B1F7-244920D39333"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:zh-jieli:ac6998:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "4194126F-3D60-4C32-A5BF-C3189DC8DA23"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:zh-jieli:ac6999_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A6DE5F1B-14FB-4FD8-8371-8E12E663E4F8"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:zh-jieli:ac6999:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "76BB702E-A868-460D-BE2C-007B595A98EE"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "cve@mitre.org"
}