The Bluetooth Classic implementation on JBL TUNE500BT devices does not properly handle the reception of continuous unsolicited LMP responses, allowing attackers in radio range to trigger a denial of service and shutdown a device by flooding the target device with LMP Feature Response data.
Link | Tags |
---|---|
https://www.jbl.com.sg/over-ear-headphones/JBL+TUNE500BT.html | product vendor advisory |
https://dl.packetstormsecurity.net/papers/general/braktooth.pdf | third party advisory technical description |