Impact
The BT122 module ceases all advertising functions upon receipt of a plaintext 'pause enceryption response' message. This flaw immediately renders the device unadvertisable, resulting in an availability outage. The weakness is classified as CWE‑440, indicating improper handling of input that leads to a disrupt service.
Affected Systems
Silabs BT122 devices are affected. No specific version information was provided, so all current revisions of the BT122 module should be considered vulnerable until a vendor patch is released.
Risk and Exploitability
The CVSS score of 5.3 marks this as a moderate‑severity denial of service with limited impact. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. It is likely that an attacker must deliver the malicious plaintext message to the BT122 module over its control channel, which suggests a local‑network or device‑level attack vector. No remote exploitation pathway is documented in the provided description, so the likelihood of widespread exploitation remains uncertain.
OpenCVE Enrichment