CVE-2018-10910

Description

A bug in Bluez may allow for the Bluetooth Discoverable state being set to on when no Bluetooth agent is registered with the system. This situation could lead to the unauthorized pairing of certain Bluetooth devices without any form of authentication. Versions before bluez 5.51 are vulnerable.

Risk Information

Base Score
3.3
MODERATE
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
EPSS Score
Exploitation Probability
0.057

Associated Vulnerability

VulnerabilityOS Platform
GNOME Bluetooth tools (USN-3856-1) gnome-bluetooth_3.28.0-2ubuntu0.1_i386.debLinux
GNOME Bluetooth tools (USN-3856-1) gnome-bluetooth_3.28.0-2ubuntu0.1_amd64.debLinux
GNOME Bluetooth tools (USN-3856-1) libgnome-bluetooth13_3.28.0-2ubuntu0.1_i386.debLinux
GNOME Bluetooth tools (USN-3856-1) libgnome-bluetooth13_3.28.0-2ubuntu0.1_amd64.debLinux
(RHSA-2020:1101) bluez security update bluez-5.44-6.el7.x86_64.rpmLinux
(RHSA-2020:1101) bluez security update bluez-cups-5.44-6.el7.x86_64.rpmLinux
(RHSA-2020:1101) bluez security update bluez-hid2hci-5.44-6.el7.x86_64.rpmLinux
(RHSA-2020:1101) bluez security update bluez-libs-5.44-6.el7.i686.rpmLinux
(RHSA-2020:1101) bluez security update bluez-libs-5.44-6.el7.x86_64.rpmLinux
(RHSA-2020:1101) bluez security update bluez-libs-devel-5.44-6.el7.i686.rpmLinux
(RHSA-2020:1101) bluez security update bluez-libs-devel-5.44-6.el7.x86_64.rpmLinux
(RHSA-2020:1912) bluez security update bluez-5.50-3.el8.x86_64.rpmLinux
(RHSA-2020:1912) bluez security update bluez-cups-5.50-3.el8.x86_64.rpmLinux
(RHSA-2020:1912) bluez security update bluez-debugsource-5.50-3.el8.i686.rpmLinux
(RHSA-2020:1912) bluez security update bluez-debugsource-5.50-3.el8.x86_64.rpmLinux
(RHSA-2020:1912) bluez security update bluez-hid2hci-5.50-3.el8.x86_64.rpmLinux
(RHSA-2020:1912) bluez security update bluez-libs-5.50-3.el8.i686.rpmLinux
(RHSA-2020:1912) bluez security update bluez-libs-5.50-3.el8.x86_64.rpmLinux
(RHSA-2020:1912) bluez security update bluez-obexd-5.50-3.el8.x86_64.rpmLinux
(CESA-2020:1912) bluez security update bluez-5.50-3.el8.x86_64.rpmLinux
(CESA-2020:1912) bluez security update bluez-cups-5.50-3.el8.x86_64.rpmLinux
(CESA-2020:1912) bluez security update bluez-hid2hci-5.50-3.el8.x86_64.rpmLinux
(CESA-2020:1912) bluez security update bluez-libs-5.50-3.el8.i686.rpmLinux
(CESA-2020:1912) bluez security update bluez-libs-5.50-3.el8.x86_64.rpmLinux
(CESA-2020:1912) bluez security update bluez-obexd-5.50-3.el8.x86_64.rpmLinux
(CESA-2020:1101) bluez security update bluez-5.44-6.el7.x86_64.rpmLinux
(CESA-2020:1101) bluez security update bluez-cups-5.44-6.el7.x86_64.rpmLinux
(CESA-2020:1101) bluez security update bluez-hid2hci-5.44-6.el7.x86_64.rpmLinux
(CESA-2020:1101) bluez security update bluez-libs-5.44-6.el7.x86_64.rpmLinux
(CESA-2020:1101) bluez security update bluez-libs-devel-5.44-6.el7.x86_64.rpmLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234