CVE Vulnerabilities

CVE-2021-34145

Published: Sep 07, 2021 | Modified: Nov 21, 2024
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
2.9 LOW
AV:A/AC:M/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The Bluetooth Classic implementation in the Cypress WICED BT stack through 2.9.0 for CYW20735B1 devices does not properly handle the reception of LMP_max_slot with an invalid Baseband packet type (and LT_ADDRESS and LT_ADDR) after completion of the LMP setup procedure, allowing attackers in radio range to trigger a denial of service (firmware crash) via a crafted LMP packet.

Affected Software

NameVendorStart VersionEnd Version
Wireless_internet_connectivity_for_embedded_devicesCypress*2.9.0 (including)
Bluez-firmwareUbuntuesm-apps/jammy*
Bluez-firmwareUbuntujammy*
Bluez-firmwareUbuntukinetic*
Bluez-firmwareUbuntulunar*
Bluez-firmwareUbuntumantic*
Bluez-firmwareUbuntutrusty*
Bluez-firmwareUbuntuupstream*
Bluez-firmwareUbuntuxenial*

References