Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-3658

Опубликовано: 27 июл. 2021
Источник: redhat
CVSS3: 4.6

Описание

bluetoothd from bluez incorrectly saves adapters' Discoverable status when a device is powered down, and restores it when powered up. If a device is powered down while discoverable, it will be discoverable when powered on again. This could lead to inadvertent exposure of the bluetooth stack to physically nearby attackers.

bluetoothd from bluez incorrectly saves adapters' Discoverable status when a device is powered down, and restores it when powered up. If a device is powered down while discoverable, it will be discoverable when powered on again. This could lead to inadvertent exposure of the bluetooth stack to physically nearby attackers.

Меры по смягчению последствий

If bluetooth is disabled or never powered on, this vulnerability is not exposed.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6bluezOut of support scope
Red Hat Enterprise Linux 7bluezOut of support scope
Red Hat Enterprise Linux 8bluezFix deferred
Red Hat Enterprise Linux 9bluezAffected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-863
https://bugzilla.redhat.com/show_bug.cgi?id=1984728bluez: adapter incorrectly restores Discoverable state after powered down

4.6 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
почти 4 года назад

bluetoothd from bluez incorrectly saves adapters' Discoverable status when a device is powered down, and restores it when powered up. If a device is powered down while discoverable, it will be discoverable when powered on again. This could lead to inadvertent exposure of the bluetooth stack to physically nearby attackers.

CVSS3: 6.5
nvd
почти 4 года назад

bluetoothd from bluez incorrectly saves adapters' Discoverable status when a device is powered down, and restores it when powered up. If a device is powered down while discoverable, it will be discoverable when powered on again. This could lead to inadvertent exposure of the bluetooth stack to physically nearby attackers.

CVSS3: 6.5
debian
почти 4 года назад

bluetoothd from bluez incorrectly saves adapters' Discoverable status ...

CVSS3: 6.5
github
почти 4 года назад

bluetoothd from bluez incorrectly saves adapters' Discoverable status when a device is powered down, and restores it when powered up. If a device is powered down while discoverable, it will be discoverable when powered on again. This could lead to inadvertent exposure of the bluetooth stack to physically nearby attackers.

CVSS3: 6.5
fstec
больше 4 лет назад

Уязвимость стека технологии Bluetooth для Linux BlueZ, связанная с неправильной авторизацией, позволяющая нарушителю получить доступ к конфиденциальным данным

4.6 Medium

CVSS3