Lucene search

K
redosRedosROS-20240918-07
HistorySep 18, 2024 - 12:00 a.m.

ROS-20240918-07

2024-09-1800:00:00
redos.red-soft.ru
8
bluez
linux
bluetooth
protocol stack
vulnerability
improper index validation
avrcp
remote exploitation
arbitrary code execution

CVSS3

7.1

Attack Vector

ADJACENT

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

7.2

Confidence

Low

EPSS

0.001

Percentile

41.7%

A vulnerability in the BlueZ Bluetooth protocol stack for Linux is related to improper index validation of the BlueZ Audio AVRCP
of the BlueZ Audio AVRCP array. Exploitation of the vulnerability could allow an attacker acting remotely,
execute arbitrary code

OSVersionArchitecturePackageVersionFilename
redos7.3x86_64bluez< 5.75-1UNKNOWN

CVSS3

7.1

Attack Vector

ADJACENT

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

7.2

Confidence

Low

EPSS

0.001

Percentile

41.7%