Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-10910

Опубликовано: 20 июл. 2018
Источник: redhat
CVSS3: 4.5
EPSS Низкий

Описание

A bug in Bluez may allow for the Bluetooth Discoverable state being set to on when no Bluetooth agent is registered with the system. This situation could lead to the unauthorized pairing of certain Bluetooth devices without any form of authentication. Versions before bluez 5.51 are vulnerable.

A bug in Bluez may allow for the Bluetooth Discoverable state being set to on when no Bluetooth agent is registered with the system. This situation could lead to the unauthorized pairing of certain Bluetooth devices without any form of authentication.

Меры по смягчению последствий

Disable Bluetooth.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6bluezNot affected
Red Hat Enterprise Linux 7bluezFixedRHSA-2020:110131.03.2020
Red Hat Enterprise Linux 8bluezFixedRHSA-2020:191228.04.2020
Red Hat Enterprise Linux 8bluezFixedRHSA-2020:191228.04.2020

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-863
https://bugzilla.redhat.com/show_bug.cgi?id=1606203bluez: failure in disabling Bluetooth discoverability in certain cases may lead to the unauthorized pairing of Bluetooth devices

EPSS

Процентиль: 18%
0.00057
Низкий

4.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.5
ubuntu
около 7 лет назад

A bug in Bluez may allow for the Bluetooth Discoverable state being set to on when no Bluetooth agent is registered with the system. This situation could lead to the unauthorized pairing of certain Bluetooth devices without any form of authentication. Versions before bluez 5.51 are vulnerable.

CVSS3: 4.5
nvd
около 7 лет назад

A bug in Bluez may allow for the Bluetooth Discoverable state being set to on when no Bluetooth agent is registered with the system. This situation could lead to the unauthorized pairing of certain Bluetooth devices without any form of authentication. Versions before bluez 5.51 are vulnerable.

CVSS3: 4.5
debian
около 7 лет назад

A bug in Bluez may allow for the Bluetooth Discoverable state being se ...

CVSS3: 3.3
github
больше 3 лет назад

A bug in Bluez may allow for the Bluetooth Discoverable state being set to on when no Bluetooth agent is registered with the system. This situation could lead to the unauthorized pairing of certain Bluetooth devices without any form of authentication. Versions before bluez 5.51 are vulnerable.

oracle-oval
почти 6 лет назад

ELSA-2020-1912: bluez security update (LOW)

EPSS

Процентиль: 18%
0.00057
Низкий

4.5 Medium

CVSS3