First published: Tue Sep 07 2021(Updated: )
The Bluetooth Classic implementation on the Texas Instruments CC256XCQFN-EM does not properly handle the reception of continuous LMP_AU_Rand packets, allowing attackers in radio range to trigger a denial of service (deadlock) of the device by flooding it with LMP_AU_Rand packets after the paging procedure.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ti Cc256xcqfn-em Firmware | ||
Ti Cc256xcqfn-em |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-34149 is a vulnerability related to the Bluetooth Classic implementation on the Texas Instruments CC256XCQFN-EM.
The severity of CVE-2021-34149 is medium with a CVSS score of 6.5.
CVE-2021-34149 allows attackers in radio range to trigger a denial of service (deadlock) by flooding the device with LMP_AU_Rand packets.
Yes, the Ti Cc256xcqfn-em firmware is vulnerable to CVE-2021-34149.
To mitigate CVE-2021-34149, it is recommended to apply the necessary firmware updates provided by Texas Instruments.