CVE-2021-31786
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
07/09/2021
Last modified:
12/07/2022
Description
The Bluetooth Classic Audio implementation on Actions ATS2815 and ATS2819 devices does not properly handle a connection attempt from a host with the same BDAddress as the current connected BT host, allowing attackers to trigger a disconnection and deadlock of the device by connecting with a forged BDAddress that matches the original connected host.
Impact
Base Score 3.x
6.50
Severity 3.x
MEDIUM
Base Score 2.0
6.10
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:actions-semi:ats2819p_firmware:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:actions-semi:ats2819p:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:actions-semi:ats2815_firmware:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:actions-semi:ats2815:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:actions-semi:ats2819_firmware:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:actions-semi:ats2819:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:actions-semi:ats2819s_firmware:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:actions-semi:ats2819s:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:actions-semi:ats2819t_firmware:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:actions-semi:ats2819t:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page