Lucene search

K
cvelistGoogleCVELIST:CVE-2024-38271
HistoryJun 26, 2024 - 3:19 p.m.

CVE-2024-38271 Denial of Service in Quick Share

2024-06-2615:19:13
CWE-404
Google
www.cve.org
6
cve-2024-38271
quickshare
denial of service
quickshare/nearby
bluetooth
offlineframe
wifi network
mitm
upgrade to version 1.0.1724.0

CVSS4

5.9

Attack Vector

ADJACENT

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

ACTIVE

CVSS:4.0/AV:A/AC:H/AT:P/PR:L/UI:A/VC:H/SC:H/VI:L/SI:L/VA:L/SA:L

EPSS

0

Percentile

10.9%

There exists a vulnerability in Quick Share/Nearby, where an attacker can force a victim to stay connected to a temporary hotspot created for the sharing. As part of the sequence of packets in a Quick Share connection over Bluetooth, the attacker forces the victim to connect to the attackerโ€™s WiFi network and then sends an OfflineFrame that crashes Quick Share.
This makes the Wifi connection to the attackerโ€™s network last, instead of returning to the old network when the Quick Share session completes, allowing the attacker to be a MiTM. We recommend upgrading to versionย 1.0.1724.0 of Quick Share or above

CNA Affected

[
  {
    "collectionURL": "https://github.com/google/nearby",
    "defaultStatus": "unaffected",
    "product": "Nearby",
    "repo": "https://github.com/google/nearby",
    "vendor": "Google",
    "versions": [
      {
        "lessThan": "1.0.1724.0",
        "status": "affected",
        "version": "0",
        "versionType": "semver"
      }
    ]
  }
]

CVSS4

5.9

Attack Vector

ADJACENT

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

ACTIVE

CVSS:4.0/AV:A/AC:H/AT:P/PR:L/UI:A/VC:H/SC:H/VI:L/SI:L/VA:L/SA:L

EPSS

0

Percentile

10.9%

Related for CVELIST:CVE-2024-38271