CVE-2024-2105

MEDIUM

Device <unknown> - DoS

Title source: llm
STIX 2.1

Description

An unauthorised attacker within bluetooth range may use an improper validation during the BLE connection request to deadlock the affected devices.

Scores

CVSS v3 6.5
EPSS 0.0006
EPSS Percentile 19.0%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-1287
Status published
Products (7)
JBL/Boombox 2
JBL/Boombox 3
JBL/Flip 5
JBL/Flip 6
JBL/Pulse 4
JBL/Pulse 5
JBL/Xtreme 3
Published Dec 10, 2025
Tracked Since Feb 18, 2026