Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-2002
HistoryMay 26, 2023 - 12:00 a.m.

CVE-2023-2002

2023-05-2600:00:00
ubuntu.com
ubuntu.com
25
hci sockets
linux kernel
unauthorized execution
management commands
bluetooth security

CVSS3

6.8

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

HIGH

CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H

EPSS

0

Percentile

10.3%

A vulnerability was found in the HCI sockets implementation due to a
missing capability check in net/bluetooth/hci_sock.c in the Linux Kernel.
This flaw allows an attacker to unauthorized execution of management
commands, compromising the confidentiality, integrity, and availability of
Bluetooth communication.

Notes

Author Note
rodrigo-zaiden attacker can take control of pairing/unpairing BT devices.
OSVersionArchitecturePackageVersionFilename
ubuntu18.04noarchlinux< 4.15.0-223.235UNKNOWN
ubuntu20.04noarchlinux< 5.4.0-162.179UNKNOWN
ubuntu22.04noarchlinux< 5.15.0-79.86UNKNOWN
ubuntu23.04noarchlinux< 6.2.0-27.28UNKNOWN
ubuntu18.04noarchlinux-aws< 4.15.0-1166.179UNKNOWN
ubuntu20.04noarchlinux-aws< 5.4.0-1109.118UNKNOWN
ubuntu22.04noarchlinux-aws< 5.15.0-1042.47UNKNOWN
ubuntu23.04noarchlinux-aws< 6.2.0-1009.9UNKNOWN
ubuntu20.04noarchlinux-aws-5.15< 5.15.0-1041.46~20.04.1UNKNOWN
ubuntu18.04noarchlinux-aws-5.4< 5.4.0-1109.118~18.04.1UNKNOWN
Rows per page:
1-10 of 761

References

CVSS3

6.8

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

HIGH

CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H

EPSS

0

Percentile

10.3%