VYPR
Medium severity6.5NVD Advisory· Published Sep 7, 2021· Updated Jun 17, 2026

CVE-2021-28135

CVE-2021-28135

Description

The Bluetooth Classic implementation in Espressif ESP-IDF 4.4 and earlier does not properly handle the reception of continuous unsolicited LMP responses, allowing attackers in radio range to trigger a denial of service (crash) in ESP32 by flooding the target device with LMP Feature Response data.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • Espressif/Esp Idf2 versions
    cpe:2.3:a:espressif:esp-idf:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:espressif:esp-idf:*:*:*:*:*:*:*:*range: <=4.4
    • (no CPE)range: <=4.4
  • Espressif/ESP-IDFdescription
  • Espressif/ESP32llm-fuzzy
    Range: <=4.4

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.