Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-9506

Опубликовано: 10 авг. 2019
Источник: redhat
CVSS3: 7
EPSS Низкий

Описание

The Bluetooth BR/EDR specification up to and including version 5.1 permits sufficiently low encryption key length and does not prevent an attacker from influencing the key length negotiation. This allows practical brute-force attacks (aka "KNOB") that can decrypt traffic and inject arbitrary ciphertext without the victim noticing.

A flaw was discovered in the Bluetooth protocol. An attacker within physical proximity to the Bluetooth connection could downgrade the encryption protocol to be trivially brute forced.

Меры по смягчению последствий

At this time there is no known mitigation if bluetooth hardware is to be continue to be used. Replacing the hardware with its wired version and disabling bluetooth may be a suitable alternative for some environments.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5kernelOut of support scope
Red Hat Enterprise Linux 6kernelWill not fix
Red Hat Enterprise Linux 7kernel-rtFixedRHSA-2019:308916.10.2019
Red Hat Enterprise Linux 7kernelFixedRHSA-2019:305516.10.2019
Red Hat Enterprise Linux 7kpatch-patchFixedRHSA-2019:307616.10.2019
Red Hat Enterprise Linux 7kernel-altFixedRHSA-2019:321729.10.2019
Red Hat Enterprise Linux 7.2 Advanced Update SupportkernelFixedRHSA-2020:146014.04.2020
Red Hat Enterprise Linux 7.3 Advanced Update SupportkernelFixedRHSA-2019:321829.10.2019
Red Hat Enterprise Linux 7.3 Telco Extended Update SupportkernelFixedRHSA-2019:321829.10.2019
Red Hat Enterprise Linux 7.3 Update Services for SAP SolutionskernelFixedRHSA-2019:321829.10.2019

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-327
https://bugzilla.redhat.com/show_bug.cgi?id=1727857hardware: bluetooth: BR/EDR encryption key negotiation attacks (KNOB)

EPSS

Процентиль: 86%
0.02975
Низкий

7 High

CVSS3

Связанные уязвимости

CVSS3: 8.1
ubuntu
почти 6 лет назад

The Bluetooth BR/EDR specification up to and including version 5.1 permits sufficiently low encryption key length and does not prevent an attacker from influencing the key length negotiation. This allows practical brute-force attacks (aka "KNOB") that can decrypt traffic and inject arbitrary ciphertext without the victim noticing.

CVSS3: 8.1
nvd
почти 6 лет назад

The Bluetooth BR/EDR specification up to and including version 5.1 permits sufficiently low encryption key length and does not prevent an attacker from influencing the key length negotiation. This allows practical brute-force attacks (aka "KNOB") that can decrypt traffic and inject arbitrary ciphertext without the victim noticing.

CVSS3: 9.3
msrc
почти 6 лет назад

Encryption Key Negotiation of Bluetooth Vulnerability

CVSS3: 8.1
debian
почти 6 лет назад

The Bluetooth BR/EDR specification up to and including version 5.1 per ...

CVSS3: 8.1
github
около 3 лет назад

The Bluetooth BR/EDR specification up to and including version 5.1 permits sufficiently low encryption key length and does not prevent an attacker from influencing the key length negotiation. This allows practical brute-force attacks (aka "KNOB") that can decrypt traffic and inject arbitrary ciphertext without the victim noticing.

EPSS

Процентиль: 86%
0.02975
Низкий

7 High

CVSS3