CVE-2021-34146 describes a denial-of-service vulnerability in the Bluetooth Classic implementation of Cypress CYW920735Q60EVB and related firmware. An attacker within radio range can crash and restart affected devices by flooding them with specific LMP packets after the paging procedure. This medium-severity vulnerability (CVSS 6.5) has a low attack complexity and requires no user interaction, leading to high availability impact. While not currently listed in CISA's KEV catalog and lacking public exploit code, it has garnered some community discussion and media coverage, indicating awareness of the underlying BrakTooth vulnerabilities.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:cypress:cyw920735q60evb-01_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:cypress:cyw20735b1_firmware:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.