« Volver al listado

CVE-2021-34143

Estado: ModificadaMedia (6.5)—

The Bluetooth Classic implementation in the Zhuhai Jieli AC6366C_DEMO_V1.0 does not properly handle the reception of continuous unsolicited LMP responses, allowing attackers in radio range to trigger a denial of service (deadlock) of the device by flooding it with LMP_AU_Rand packets after paging procedure. User intervention is required to restart the device.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2021-34143",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.1,
          "accessVector": "ADJACENT_NETWORK",
          "vectorString": "AV:A/AC:L/Au:N/C:N/I:N/A:C",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 6.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 6.5,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "ADJACENT_NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2021-09-07T07:15:07.237",
  "references": [
    {
      "url": "https://dl.packetstormsecurity.net/papers/general/braktooth.pdf",
      "tags": [
        "Broken Link"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://github.com/Jieli-Tech/fw-AC63_BT_SDK",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://launchstudio.bluetooth.com/ListingDetails/91371",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://dl.packetstormsecurity.net/papers/general/braktooth.pdf",
      "tags": [
        "Broken Link"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://github.com/Jieli-Tech/fw-AC63_BT_SDK",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://launchstudio.bluetooth.com/ListingDetails/91371",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The Bluetooth Classic implementation in the Zhuhai Jieli AC6366C_DEMO_V1.0 does not properly handle the reception of continuous unsolicited LMP responses, allowing attackers in radio range to trigger a denial of service (deadlock) of the device by flooding it with LMP_AU_Rand packets after paging procedure. User intervention is required to restart the device."
    },
    {
      "lang": "es",
      "value": "Una implementación de Bluetooth Classic en el Zhuhai Jieli versión  AC6366C_DEMO_V1.0, no maneja apropiadamente la recepción de respuestas LMP continuas no solicitadas, permitiendo a atacantes en el rango de radio desencadenar una denegación de servicio (bloqueo del firmware) del dispositivo inundándolo con paquetes LMP_AU_Rand después del procedimiento de paginación. Es requerida una intervención del usuario para reiniciar el dispositivo"
    }
  ],
  "lastModified": "2026-06-17T03:55:30.410",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:zh-jieli:fw-ac63_bt_sdk:1.0.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0F28F062-BF1F-410F-88A8-6803A3597CDE"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:zh-jieli:ac6936:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "D65C6E62-5D22-4E63-91D9-7BA950C965D2"
            },
            {
              "criteria": "cpe:2.3:h:zh-jieli:ac6951:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "3D8CE668-DAA3-4260-81DC-263D02371CC4"
            },
            {
              "criteria": "cpe:2.3:h:zh-jieli:ac6952:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "4E8D2A79-973F-4623-8B69-FB84A7FD1523"
            },
            {
              "criteria": "cpe:2.3:h:zh-jieli:ac6954:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "DD431683-3C41-4E33-9CBF-3C8A48349864"
            },
            {
              "criteria": "cpe:2.3:h:zh-jieli:ac6955:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "AE0BEAC2-6AD0-4ABC-AAA0-D6A92381738F"
            },
            {
              "criteria": "cpe:2.3:h:zh-jieli:ac6956:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "BF79B45C-5363-4B0A-A920-76BC2A928F72"
            },
            {
              "criteria": "cpe:2.3:h:zh-jieli:ac6963:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "20CCB0EB-0BA5-4791-806A-43E76EDC4A14"
            },
            {
              "criteria": "cpe:2.3:h:zh-jieli:ac6965:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "6C109D9C-60B0-4F68-9425-CF56C27010F6"
            },
            {
              "criteria": "cpe:2.3:h:zh-jieli:ac6966:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "D823A1B8-52F8-4B77-8E88-458C3027F756"
            },
            {
              "criteria": "cpe:2.3:h:zh-jieli:ac6969:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "2CD608BB-12D0-4741-9C29-C2F2152D85F1"
            },
            {
              "criteria": "cpe:2.3:h:zh-jieli:ac6973:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "368384EE-1C0E-45DE-BE6A-7FF65842B62E"
            },
            {
              "criteria": "cpe:2.3:h:zh-jieli:ac6976:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "7477A947-398B-4E6A-A751-EFA5A17B381E"
            },
            {
              "criteria": "cpe:2.3:h:zh-jieli:ac6983:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "EBD55EDB-A91C-45FF-99F7-E8204E8C2D54"
            },
            {
              "criteria": "cpe:2.3:h:zh-jieli:ac6986:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "030B8002-E03A-470A-AA02-40456FA4FE6C"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}