Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2021-3658

Опубликовано: 02 мар. 2022
Источник: ubuntu
Приоритет: low
CVSS2: 3.3
CVSS3: 6.5

Описание

bluetoothd from bluez incorrectly saves adapters' Discoverable status when a device is powered down, and restores it when powered up. If a device is powered down while discoverable, it will be discoverable when powered on again. This could lead to inadvertent exposure of the bluetooth stack to physically nearby attackers.

РелизСтатусПримечание
bionic

not-affected

code not present
devel

not-affected

5.62-0ubuntu1
esm-infra-legacy/trusty

DNE

esm-infra/bionic

not-affected

code not present
esm-infra/focal

released

5.53-0ubuntu3.4
esm-infra/xenial

not-affected

code not present
focal

released

5.53-0ubuntu3.4
hirsute

released

5.56-0ubuntu4.3
impish

released

5.60-0ubuntu2.1
jammy

not-affected

5.62-0ubuntu1

Показывать по

3.3 Low

CVSS2

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.6
redhat
больше 4 лет назад

bluetoothd from bluez incorrectly saves adapters' Discoverable status when a device is powered down, and restores it when powered up. If a device is powered down while discoverable, it will be discoverable when powered on again. This could lead to inadvertent exposure of the bluetooth stack to physically nearby attackers.

CVSS3: 6.5
nvd
почти 4 года назад

bluetoothd from bluez incorrectly saves adapters' Discoverable status when a device is powered down, and restores it when powered up. If a device is powered down while discoverable, it will be discoverable when powered on again. This could lead to inadvertent exposure of the bluetooth stack to physically nearby attackers.

CVSS3: 6.5
debian
почти 4 года назад

bluetoothd from bluez incorrectly saves adapters' Discoverable status ...

CVSS3: 6.5
github
почти 4 года назад

bluetoothd from bluez incorrectly saves adapters' Discoverable status when a device is powered down, and restores it when powered up. If a device is powered down while discoverable, it will be discoverable when powered on again. This could lead to inadvertent exposure of the bluetooth stack to physically nearby attackers.

CVSS3: 6.5
fstec
больше 4 лет назад

Уязвимость стека технологии Bluetooth для Linux BlueZ, связанная с неправильной авторизацией, позволяющая нарушителю получить доступ к конфиденциальным данным

3.3 Low

CVSS2

6.5 Medium

CVSS3