Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-3658

Опубликовано: 02 мар. 2022
Источник: nvd
CVSS3: 6.5
CVSS2: 3.3
EPSS Низкий

Описание

bluetoothd from bluez incorrectly saves adapters' Discoverable status when a device is powered down, and restores it when powered up. If a device is powered down while discoverable, it will be discoverable when powered on again. This could lead to inadvertent exposure of the bluetooth stack to physically nearby attackers.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:bluez:bluez:*:*:*:*:*:*:*:*
Версия до 5.61 (исключая)
Конфигурация 2
cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*

EPSS

Процентиль: 21%
0.0007
Низкий

6.5 Medium

CVSS3

3.3 Low

CVSS2

Дефекты

CWE-863
CWE-863

Связанные уязвимости

CVSS3: 6.5
ubuntu
почти 4 года назад

bluetoothd from bluez incorrectly saves adapters' Discoverable status when a device is powered down, and restores it when powered up. If a device is powered down while discoverable, it will be discoverable when powered on again. This could lead to inadvertent exposure of the bluetooth stack to physically nearby attackers.

CVSS3: 4.6
redhat
больше 4 лет назад

bluetoothd from bluez incorrectly saves adapters' Discoverable status when a device is powered down, and restores it when powered up. If a device is powered down while discoverable, it will be discoverable when powered on again. This could lead to inadvertent exposure of the bluetooth stack to physically nearby attackers.

CVSS3: 6.5
debian
почти 4 года назад

bluetoothd from bluez incorrectly saves adapters' Discoverable status ...

CVSS3: 6.5
github
почти 4 года назад

bluetoothd from bluez incorrectly saves adapters' Discoverable status when a device is powered down, and restores it when powered up. If a device is powered down while discoverable, it will be discoverable when powered on again. This could lead to inadvertent exposure of the bluetooth stack to physically nearby attackers.

CVSS3: 6.5
fstec
больше 4 лет назад

Уязвимость стека технологии Bluetooth для Linux BlueZ, связанная с неправильной авторизацией, позволяющая нарушителю получить доступ к конфиденциальным данным

EPSS

Процентиль: 21%
0.0007
Низкий

6.5 Medium

CVSS3

3.3 Low

CVSS2

Дефекты

CWE-863
CWE-863