Denial of Service Vulnerability in Cypress Bluetooth Transceiver
CVE-2021-34146
6.5MEDIUM
What is CVE-2021-34146?
The Bluetooth Classic implementation in Cypress's CYW920735Q60EVB transceiver is susceptible to a denial of service attack due to improper handling of unsolicited LMP responses. Attackers within radio range can exploit this vulnerability by inundating the device with LMP_AU_Rand packets post-paging procedure, causing it to crash and restart. This impacts device availability and can disrupt normal operations.
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
