Vulnerabilities > Actions Semi

DATE CVE VULNERABILITY TITLE RISK
2021-11-30 CVE-2021-31787 Allocation of Resources Without Limits or Throttling vulnerability in Actions-Semi products
The Bluetooth Classic implementation on Actions ATS2815 chipsets does not properly handle the reception of continuous unsolicited LMP responses, allowing attackers in radio range to trigger a denial of service and shutdown of a device by flooding the target device with LMP_features_res packets.
low complexity
actions-semi CWE-770
6.1
2021-09-07 CVE-2021-31785 Improper Locking vulnerability in Actions-Semi products
The Bluetooth Classic implementation on Actions ATS2815 and ATS2819 chipsets does not properly handle the reception of multiple LMP_host_connection_req packets, allowing attackers in radio range to trigger a denial of service (deadlock) of the device via crafted LMP packets.
low complexity
actions-semi CWE-667
6.1
2021-09-07 CVE-2021-31786 Improper Locking vulnerability in Actions-Semi products
The Bluetooth Classic Audio implementation on Actions ATS2815 and ATS2819 devices does not properly handle a connection attempt from a host with the same BDAddress as the current connected BT host, allowing attackers to trigger a disconnection and deadlock of the device by connecting with a forged BDAddress that matches the original connected host.
low complexity
actions-semi CWE-667
6.1