bluetooth records
16 published records for vendor bluetooth.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 25%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-287 Improper Authentication3
- CWE-863 Incorrect Authorization3
- CWE-294 Authentication Bypass by Capture-replay2
- CWE-203 Observable Discrepancy2
- CWE-757 Selection of Less-Secure Algorithm During Negotiation ('Algorithm Downgrade')1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
16 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
37Monitor | CVE-2011-1265No exploit | The Bluetooth Stack 2.1 in Microsoft Windows Vista SP1 and SP2 and Windows 7 Gold and SP1 does not prevent access to objects in memory that bluetooth · bluetooth stack · CWE-94 | High8.8 | — | 5.9% | Jul 13, 2011 |
35Monitor | CVE-2020-26559No exploit | Bluetooth Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device (participating in the provisioning protocbluetooth · mesh profile · CWE-863 | High8.8 | — | 0.9% | May 24, 2021 |
32Monitor | CVE-2020-26560No exploit | Bluetooth Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device, reflecting the authentication evidence fbluetooth · mesh profile · CWE-863 | High8.1 | — | 0.9% | May 24, 2021 |
30Monitor | CVE-2020-26556No exploit | Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device, able to conduct a successful brute-force attack onbluetooth · bluetooth core specification · CWE-307 | High7.5 | — | 0.9% | May 24, 2021 |
30Monitor | CVE-2020-26557No exploit | Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device (without possession of the AuthValue used in the prbluetooth · mesh profile · CWE-287 | High7.5 | — | 0.8% | May 24, 2021 |
30Monitor | CVE-2022-25837No exploit | Bluetooth® Pairing in Bluetooth Core Specification v1.0B through v5.3 may permit an unauthenticated MITM to acquire credentials with two paibluetooth · bluetooth core specification · CWE-294 | High7.5 | — | 0.4% | Dec 12, 2022 |
30Monitor | CVE-2022-25836No exploit | Bluetooth® Low Energy Pairing in Bluetooth Core Specification v4.0 through v5.3 may permit an unauthenticated MITM to acquire credentials wibluetooth · bluetooth core specification · CWE-294 | High7.5 | — | 0.4% | Dec 12, 2022 |
27Monitor | CVE-2023-24023No exploit | Bluetooth BR/EDR devices with Secure Simple Pairing and Secure Connections pairing in Bluetooth Core Specification 4.2 through 5.4 allow cerbluetooth · bluetooth core specification | Medium6.8 | — | 1.3% | Nov 28, 2023 |
25Monitor | CVE-2020-15802Proof of concept | Devices supporting Bluetooth before 5.1 may allow man-in-the-middle attacks, aka BLURtooth.bluetooth · bluetooth core specification · CWE-287 | Medium5.9 | — | 7.1% | Sep 11, 2020 |
25Monitor | CVE-2020-10134No exploit | Bluetooth devices supporting LE and specific BR/EDR implementations are vulnerable to method confusion attacksbluetooth · bluetooth core · CWE-351 | Medium6.3 | — | 0.7% | May 19, 2020 |
22Monitor | CVE-2020-10135Proof of concept | Bluetooth devices supporting BR/EDR v5.2 and earlier are vulnerable to impersonation attacksbluetooth · bluetooth core · CWE-757 | Medium5.4 | — | 2.4% | May 19, 2020 |
21Monitor | CVE-2020-26555No exploit | Bluetooth legacy BR/EDR PIN code pairing in Bluetooth Core Specification 1.0B through 5.2 may permit an unauthenticated nearby device to spobluetooth · bluetooth core specification · CWE-863 | Medium5.4 | — | 0.9% | May 24, 2021 |
21Monitor | CVE-2021-31615No exploit | Unencrypted Bluetooth Low Energy baseband links in Bluetooth Core Specifications 4.0 through 5.2 may permit an adjacent device to inject a cbluetooth · bluetooth core specification · CWE-362 | Medium5.3 | — | 0.4% | Jun 25, 2021 |
17Monitor | CVE-2022-24695No exploit | Bluetooth Classic in Bluetooth Core Specification through 5.3 does not properly conceal device information for Bluetooth transceivers in Nonbluetooth · bluetooth core specification · CWE-203 | Medium4.3 | — | 0.4% | Jun 2, 2023 |
17Monitor | CVE-2020-35473No exploit | An information leakage vulnerability in the Bluetooth Low Energy advertisement scan response in Bluetooth Core Specifications 4.0 through 5.bluetooth · bluetooth core specification · CWE-203 | Medium4.3 | — | 0.4% | Nov 8, 2022 |
16Monitor | CVE-2020-26558No exploit | Bluetooth LE and BR/EDR secure pairing in Bluetooth Core Specification 2.1 through 5.2 may permit a nearby man-in-the-middle attacker to idebluetooth · bluetooth core specification · CWE-287 | Medium4.2 | — | 0.9% | May 24, 2021 |
- CVE-2011-126537Monitor
The Bluetooth Stack 2.1 in Microsoft Windows Vista SP1 and SP2 and Windows 7 Gold and SP1 does not prevent access to objects in memory that
HighCVSS 8.8No exploitEPSS 6%bluetooth · bluetooth stackJul 13, 2011
- CVE-2020-2655935Monitor
Bluetooth Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device (participating in the provisioning protoc
HighCVSS 8.8No exploitEPSS 1%bluetooth · mesh profileMay 24, 2021
- CVE-2020-2656032Monitor
Bluetooth Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device, reflecting the authentication evidence f
HighCVSS 8.1No exploitEPSS 1%bluetooth · mesh profileMay 24, 2021
- CVE-2020-2655630Monitor
Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device, able to conduct a successful brute-force attack on
HighCVSS 7.5No exploitEPSS 1%bluetooth · bluetooth core specificationMay 24, 2021
- CVE-2020-2655730Monitor
Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device (without possession of the AuthValue used in the pr
HighCVSS 7.5No exploitEPSS 1%bluetooth · mesh profileMay 24, 2021
- CVE-2022-2583730Monitor
Bluetooth® Pairing in Bluetooth Core Specification v1.0B through v5.3 may permit an unauthenticated MITM to acquire credentials with two pai
HighCVSS 7.5No exploitEPSS 0%bluetooth · bluetooth core specificationDec 12, 2022
- CVE-2022-2583630Monitor
Bluetooth® Low Energy Pairing in Bluetooth Core Specification v4.0 through v5.3 may permit an unauthenticated MITM to acquire credentials wi
HighCVSS 7.5No exploitEPSS 0%bluetooth · bluetooth core specificationDec 12, 2022
- CVE-2023-2402327Monitor
Bluetooth BR/EDR devices with Secure Simple Pairing and Secure Connections pairing in Bluetooth Core Specification 4.2 through 5.4 allow cer
MediumCVSS 6.8No exploitEPSS 1%bluetooth · bluetooth core specificationNov 28, 2023
- CVE-2020-1580225Monitor
Devices supporting Bluetooth before 5.1 may allow man-in-the-middle attacks, aka BLURtooth.
MediumCVSS 5.9Proof of conceptEPSS 7%bluetooth · bluetooth core specificationSep 11, 2020
- CVE-2020-1013425Monitor
Bluetooth devices supporting LE and specific BR/EDR implementations are vulnerable to method confusion attacks
MediumCVSS 6.3No exploitEPSS 1%bluetooth · bluetooth coreMay 19, 2020
- CVE-2020-1013522Monitor
Bluetooth devices supporting BR/EDR v5.2 and earlier are vulnerable to impersonation attacks
MediumCVSS 5.4Proof of conceptEPSS 2%bluetooth · bluetooth coreMay 19, 2020
- CVE-2020-2655521Monitor
Bluetooth legacy BR/EDR PIN code pairing in Bluetooth Core Specification 1.0B through 5.2 may permit an unauthenticated nearby device to spo
MediumCVSS 5.4No exploitEPSS 1%bluetooth · bluetooth core specificationMay 24, 2021
- CVE-2021-3161521Monitor
Unencrypted Bluetooth Low Energy baseband links in Bluetooth Core Specifications 4.0 through 5.2 may permit an adjacent device to inject a c
MediumCVSS 5.3No exploitEPSS 0%bluetooth · bluetooth core specificationJun 25, 2021
- CVE-2022-2469517Monitor
Bluetooth Classic in Bluetooth Core Specification through 5.3 does not properly conceal device information for Bluetooth transceivers in Non
MediumCVSS 4.3No exploitEPSS 0%bluetooth · bluetooth core specificationJun 2, 2023
- CVE-2020-3547317Monitor
An information leakage vulnerability in the Bluetooth Low Energy advertisement scan response in Bluetooth Core Specifications 4.0 through 5.
MediumCVSS 4.3No exploitEPSS 0%bluetooth · bluetooth core specificationNov 8, 2022
- CVE-2020-2655816Monitor
Bluetooth LE and BR/EDR secure pairing in Bluetooth Core Specification 2.1 through 5.2 may permit a nearby man-in-the-middle attacker to ide
MediumCVSS 4.2No exploitEPSS 1%bluetooth · bluetooth core specificationMay 24, 2021