Input validation error in Intel products - #VU56330
Published: September 6, 2021
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to the Bluetooth Classic implementations does not properly handle the reception of a malformed LMP timing accuracy response followed by multiple re-connections to the target link slave. A remote attacker can pass specially crafted input to the application and perform a denial of service (DoS) attack.
Affected software
CYW920735Q60EVB
Intel Wi-Fi 6 AX200
CYW20735B1
Pocophone F1 (WCN3990)
Remediation
CYW20735B1 - update to 2.9.0