Описание
In the Airoha Bluetooth audio SDK, there is a possible way to pair Bluetooth audio device without user consent. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
EPSS
Процентиль: 94%
0.06943
Низкий
8.8 High
CVSS3
Дефекты
CWE-863
Связанные уязвимости
CVSS3: 8.8
github
около 1 года назад
In the Airoha Bluetooth audio SDK, there is a possible way to pair Bluetooth audio device without user consent. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVSS3: 6.3
fstec
около 1 года назад
Уязвимость компонента BR/EDR Bluetooth-чипов TWS-наушников Airoha Technology, позволяющая нарушителю обойти существующие ограничения безопасности
EPSS
Процентиль: 94%
0.06943
Низкий
8.8 High
CVSS3
Дефекты
CWE-863