Уязвимость несанкционированного подключения HID-устройств в BlueZ через Bluetooth
Описание
Хосты Bluetooth HID в BlueZ могут позволять неаутентифицированному устройству с ролью Peripheral инициировать и устанавливать зашифрованное соединение, а также принимать отчеты HID-клавиатуры. Это потенциально может привести к внедрению HID-сообщений без взаимодействия пользователя в роли Central для авторизации такого доступа. Примером затронутого пакета является bluez 5.64-0ubuntu1 в Ubuntu 22.04 LTS.
ПРИМЕЧАНИЕ: в некоторых случаях меры по устранению CVE-2020-0556 уже могли решить эту проблему.
Затронутые версии ПО
- BlueZ (например, bluez 5.64-0ubuntu1 в Ubuntu 22.04 LTS)
Тип уязвимости
- Неавторизованный доступ
- Внедрение данных
Ссылки
- Release Notes
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Not Applicable
- Mailing ListPatch
- Third Party Advisory
- Mailing ListThird Party Advisory
- Mailing List
- Mailing List
- Third Party Advisory
- Third Party Advisory
- Release Notes
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Not Applicable
- Mailing ListPatch
- Third Party Advisory
- Mailing ListThird Party Advisory
Уязвимые конфигурации
Одновременно
Одновременно
Одновременно
Одно из
Одновременно
Одно из
Одновременно
Одно из
Одновременно
Одновременно
Одновременно
Одно из
Одно из
EPSS
6.3 Medium
CVSS3
Дефекты
Связанные уязвимости
Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate and establish an encrypted connection, and accept HID keyboard reports, potentially permitting injection of HID messages when no user interaction has occurred in the Central role to authorize such access. An example affected package is bluez 5.64-0ubuntu1 in Ubuntu 22.04LTS. NOTE: in some cases, a CVE-2020-0556 mitigation would have already addressed this Bluetooth HID Hosts issue.
Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate and establish an encrypted connection, and accept HID keyboard reports, potentially permitting injection of HID messages when no user interaction has occurred in the Central role to authorize such access. An example affected package is bluez 5.64-0ubuntu1 in Ubuntu 22.04LTS. NOTE: in some cases, a CVE-2020-0556 mitigation would have already addressed this Bluetooth HID Hosts issue.
Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral ...
Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate and establish an encrypted connection, and accept HID keyboard reports, potentially permitting injection of HID messages when no user interaction has occurred in the Central role to authorize such access. An example affected package is bluez 5.64-0ubuntu1 in Ubuntu 22.04LTS. NOTE: in some cases, a CVE-2020-0556 mitigation would have already addressed this Bluetooth HID Hosts issue.
EPSS
6.3 Medium
CVSS3