CVSS3
Attack Vector
ADJACENT
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
Percentile
29.8%
BlueZ before 5.59 allows physically proximate attackers to obtain sensitive
information because profiles/audio/avrcp.c does not validate params_len.
Author | Note |
---|---|
rodrigo-zaiden | this and CVE-2022-39177 tracked in same LP bug |