Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-9770

Опубликовано: 15 сент. 2020
Источник: redhat
CVSS3: 6.6
EPSS Низкий

Описание

A logic issue was addressed with improved state management. This issue is fixed in iOS 13.4 and iPadOS 13.4. An attacker in a privileged network position may be able to intercept Bluetooth traffic.

Отчет

The research paper describes that Bluetooth Low Energy connections managed through bluetoothctl control or via D-Bus API are not vulnerable to this attack as they strictly follow the proactive authentication specification. Connections that are managed by gatttool are among those that may be vulnerable.

Меры по смягчению последствий

Bluetooth Low Energy can be disabled altogether if it is not required, using the configuration below. This will prevent BLE devices from connecting with the host, disabling this attack ControllerMode=bredr

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7bluezWill not fix
Red Hat Enterprise Linux 8bluezWill not fix
Red Hat Enterprise Linux 9bluezAffected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-305

EPSS

Процентиль: 60%
0.00405
Низкий

6.6 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
почти 6 лет назад

A logic issue was addressed with improved state management. This issue is fixed in iOS 13.4 and iPadOS 13.4. An attacker in a privileged network position may be able to intercept Bluetooth traffic.

CVSS3: 6.5
nvd
почти 6 лет назад

A logic issue was addressed with improved state management. This issue is fixed in iOS 13.4 and iPadOS 13.4. An attacker in a privileged network position may be able to intercept Bluetooth traffic.

github
больше 3 лет назад

A logic issue was addressed with improved state management. This issue is fixed in iOS 13.4 and iPadOS 13.4. An attacker in a privileged network position may be able to intercept Bluetooth traffic.

EPSS

Процентиль: 60%
0.00405
Низкий

6.6 Medium

CVSS3