CVE-2021-28135

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
07/09/2021
Last modified:
12/07/2022

Description

The Bluetooth Classic implementation in Espressif ESP-IDF 4.4 and earlier does not properly handle the reception of continuous unsolicited LMP responses, allowing attackers in radio range to trigger a denial of service (crash) in ESP32 by flooding the target device with LMP Feature Response data.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:espressif:esp-idf:*:*:*:*:*:*:*:* 4.4 (including)