Lucene search

K
cveRedhatCVE-2018-10910
HistoryJan 28, 2019 - 3:29 p.m.

CVE-2018-10910

2019-01-2815:29:00
CWE-863
redhat
web.nvd.nist.gov
208
cve-2018-10910
bluez
bluetooth
discoverable
vulnerability

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

CVSS3

4.5

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L

AI Score

3.9

Confidence

High

EPSS

0

Percentile

12.8%

A bug in Bluez may allow for the Bluetooth Discoverable state being set to on when no Bluetooth agent is registered with the system. This situation could lead to the unauthorized pairing of certain Bluetooth devices without any form of authentication. Versions before bluez 5.51 are vulnerable.

Affected configurations

Nvd
Vulners
Node
bluezbluezRange<5.51
Node
canonicalubuntu_linuxMatch18.04lts
VendorProductVersionCPE
bluezbluez*cpe:2.3:a:bluez:bluez:*:*:*:*:*:*:*:*
canonicalubuntu_linux18.04cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*

CNA Affected

[
  {
    "product": "bluez",
    "vendor": "The Bluez Project",
    "versions": [
      {
        "status": "affected",
        "version": "before 5.51"
      }
    ]
  }
]

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

CVSS3

4.5

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L

AI Score

3.9

Confidence

High

EPSS

0

Percentile

12.8%