Impact
An unencrypted 'pause encryption request' message sent to the BT122 module triggers a denial of service. The module does not perform proper input validation on this control message, allowing an attacker to repeatedly issue the command and exhaust system resources until the device becomes unresponsive. The vulnerability falls under CWE-440, indicating incomplete input validation leading to denial of service. The impact of exploitation is loss of availability of the affected device; there is no known path to compromise confidentiality or integrity.
Affected Systems
The vulnerability affects Silabs BT122 devices. No specific firmware versions are listed, so any current or past releases of the BT122 module are potentially impacted until a patch is applied.
Risk and Exploitability
The CVSS score is 7.1, which classifies the risk as high. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting that the exploitation likelihood may not be well quantified yet. The likely attack vector is through the BT122’s communication interface, where an unauthenticated, plaintext pause request can be injected, possibly via network, serial, or other control channels. Based on the description, it is inferred that the attacker must have access to the communication path used by the BT122 module.
OpenCVE Enrichment