Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-10370

Опубликовано: 07 фев. 2022
Источник: redhat
CVSS3: 5.8

Описание

Certain Cypress (and Broadcom) Wireless Combo chips such as CYW43455, when a 2021-01-26 Bluetooth firmware update is not present, allow a Bluetooth outage via a "Spectra" attack.

A lateral-movement denial of service vulnerability was found in resource-sharing Bluetooth hardware. By obtaining code execution on the Bluetooth or Wifi chip, an attacker can perform a lateral denial of service attack on a chip's shared memory resources, impacting the system's availability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6bluezNot affected
Red Hat Enterprise Linux 7bluezNot affected
Red Hat Enterprise Linux 8bluezNot affected
Red Hat Enterprise Linux 9bluezNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-94
https://bugzilla.redhat.com/show_bug.cgi?id=2052676Bluez: bluetooth firmware has Sweyntooth and Spectra issues

5.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
около 1 года назад

Certain Cypress (and Broadcom) Wireless Combo chips such as CYW43455, when a 2021-01-26 Bluetooth firmware update is not present, allow a Bluetooth outage via a "Spectra" attack.

CVSS3: 8.8
nvd
около 1 года назад

Certain Cypress (and Broadcom) Wireless Combo chips such as CYW43455, when a 2021-01-26 Bluetooth firmware update is not present, allow a Bluetooth outage via a "Spectra" attack.

CVSS3: 8.8
debian
около 1 года назад

Certain Cypress (and Broadcom) Wireless Combo chips such as CYW43455, ...

CVSS3: 8.8
github
около 1 года назад

Certain Cypress (and Broadcom) Wireless Combo chips such as CYW43455, when a 2021-01-26 Bluetooth firmware update is not present, allow a Bluetooth outage via a "Spectra" attack.

5.8 Medium

CVSS3