Записи Bluetooth
16 опубликованных записей вендора bluetooth.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 25 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-287 Improper Authentication3
- CWE-863 Incorrect Authorization3
- CWE-294 Authentication Bypass by Capture-replay2
- CWE-203 Observable Discrepancy2
- CWE-757 Selection of Less-Secure Algorithm During Negotiation ('Algorithm Downgrade')1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
16 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
37Наблюдать | CVE-2011-1265Эксплойта нет | The Bluetooth Stack 2.1 in Microsoft Windows Vista SP1 and SP2 and Windows 7 Gold and SP1 does not prevent access to objects in memory that bluetooth · bluetooth stack · CWE-94 | Высокая8,8 | — | 5,9 % | 13 июл. 2011 г. |
35Наблюдать | CVE-2020-26559Эксплойта нет | Bluetooth Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device (participating in the provisioning protocbluetooth · mesh profile · CWE-863 | Высокая8,8 | — | 0,9 % | 24 мая 2021 г. |
32Наблюдать | CVE-2020-26560Эксплойта нет | Bluetooth Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device, reflecting the authentication evidence fbluetooth · mesh profile · CWE-863 | Высокая8,1 | — | 0,9 % | 24 мая 2021 г. |
30Наблюдать | CVE-2020-26556Эксплойта нет | Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device, able to conduct a successful brute-force attack onbluetooth · bluetooth core specification · CWE-307 | Высокая7,5 | — | 0,9 % | 24 мая 2021 г. |
30Наблюдать | CVE-2020-26557Эксплойта нет | Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device (without possession of the AuthValue used in the prbluetooth · mesh profile · CWE-287 | Высокая7,5 | — | 0,8 % | 24 мая 2021 г. |
30Наблюдать | CVE-2022-25837Эксплойта нет | Bluetooth® Pairing in Bluetooth Core Specification v1.0B through v5.3 may permit an unauthenticated MITM to acquire credentials with two paibluetooth · bluetooth core specification · CWE-294 | Высокая7,5 | — | 0,4 % | 12 дек. 2022 г. |
30Наблюдать | CVE-2022-25836Эксплойта нет | Bluetooth® Low Energy Pairing in Bluetooth Core Specification v4.0 through v5.3 may permit an unauthenticated MITM to acquire credentials wibluetooth · bluetooth core specification · CWE-294 | Высокая7,5 | — | 0,4 % | 12 дек. 2022 г. |
27Наблюдать | CVE-2023-24023Эксплойта нет | Bluetooth BR/EDR devices with Secure Simple Pairing and Secure Connections pairing in Bluetooth Core Specification 4.2 through 5.4 allow cerbluetooth · bluetooth core specification | Средняя6,8 | — | 1,3 % | 28 нояб. 2023 г. |
25Наблюдать | CVE-2020-15802Proof of concept | Devices supporting Bluetooth before 5.1 may allow man-in-the-middle attacks, aka BLURtooth.bluetooth · bluetooth core specification · CWE-287 | Средняя5,9 | — | 7,1 % | 11 сент. 2020 г. |
25Наблюдать | CVE-2020-10134Эксплойта нет | Bluetooth devices supporting LE and specific BR/EDR implementations are vulnerable to method confusion attacksbluetooth · bluetooth core · CWE-351 | Средняя6,3 | — | 0,7 % | 19 мая 2020 г. |
22Наблюдать | CVE-2020-10135Proof of concept | Bluetooth devices supporting BR/EDR v5.2 and earlier are vulnerable to impersonation attacksbluetooth · bluetooth core · CWE-757 | Средняя5,4 | — | 2,4 % | 19 мая 2020 г. |
21Наблюдать | CVE-2020-26555Эксплойта нет | Bluetooth legacy BR/EDR PIN code pairing in Bluetooth Core Specification 1.0B through 5.2 may permit an unauthenticated nearby device to spobluetooth · bluetooth core specification · CWE-863 | Средняя5,4 | — | 0,9 % | 24 мая 2021 г. |
21Наблюдать | CVE-2021-31615Эксплойта нет | Unencrypted Bluetooth Low Energy baseband links in Bluetooth Core Specifications 4.0 through 5.2 may permit an adjacent device to inject a cbluetooth · bluetooth core specification · CWE-362 | Средняя5,3 | — | 0,4 % | 25 июн. 2021 г. |
17Наблюдать | CVE-2022-24695Эксплойта нет | Bluetooth Classic in Bluetooth Core Specification through 5.3 does not properly conceal device information for Bluetooth transceivers in Nonbluetooth · bluetooth core specification · CWE-203 | Средняя4,3 | — | 0,4 % | 2 июн. 2023 г. |
17Наблюдать | CVE-2020-35473Эксплойта нет | An information leakage vulnerability in the Bluetooth Low Energy advertisement scan response in Bluetooth Core Specifications 4.0 through 5.bluetooth · bluetooth core specification · CWE-203 | Средняя4,3 | — | 0,4 % | 8 нояб. 2022 г. |
16Наблюдать | CVE-2020-26558Эксплойта нет | Bluetooth LE and BR/EDR secure pairing in Bluetooth Core Specification 2.1 through 5.2 may permit a nearby man-in-the-middle attacker to idebluetooth · bluetooth core specification · CWE-287 | Средняя4,2 | — | 0,9 % | 24 мая 2021 г. |
- CVE-2011-126537Наблюдать
The Bluetooth Stack 2.1 in Microsoft Windows Vista SP1 and SP2 and Windows 7 Gold and SP1 does not prevent access to objects in memory that
ВысокаяCVSS 8,8Эксплойта нетEPSS 6 %bluetooth · bluetooth stack13 июл. 2011 г.
- CVE-2020-2655935Наблюдать
Bluetooth Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device (participating in the provisioning protoc
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %bluetooth · mesh profile24 мая 2021 г.
- CVE-2020-2656032Наблюдать
Bluetooth Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device, reflecting the authentication evidence f
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %bluetooth · mesh profile24 мая 2021 г.
- CVE-2020-2655630Наблюдать
Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device, able to conduct a successful brute-force attack on
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %bluetooth · bluetooth core specification24 мая 2021 г.
- CVE-2020-2655730Наблюдать
Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device (without possession of the AuthValue used in the pr
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %bluetooth · mesh profile24 мая 2021 г.
- CVE-2022-2583730Наблюдать
Bluetooth® Pairing in Bluetooth Core Specification v1.0B through v5.3 may permit an unauthenticated MITM to acquire credentials with two pai
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %bluetooth · bluetooth core specification12 дек. 2022 г.
- CVE-2022-2583630Наблюдать
Bluetooth® Low Energy Pairing in Bluetooth Core Specification v4.0 through v5.3 may permit an unauthenticated MITM to acquire credentials wi
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %bluetooth · bluetooth core specification12 дек. 2022 г.
- CVE-2023-2402327Наблюдать
Bluetooth BR/EDR devices with Secure Simple Pairing and Secure Connections pairing in Bluetooth Core Specification 4.2 through 5.4 allow cer
СредняяCVSS 6,8Эксплойта нетEPSS 1 %bluetooth · bluetooth core specification28 нояб. 2023 г.
- CVE-2020-1580225Наблюдать
Devices supporting Bluetooth before 5.1 may allow man-in-the-middle attacks, aka BLURtooth.
СредняяCVSS 5,9Proof of conceptEPSS 7 %bluetooth · bluetooth core specification11 сент. 2020 г.
- CVE-2020-1013425Наблюдать
Bluetooth devices supporting LE and specific BR/EDR implementations are vulnerable to method confusion attacks
СредняяCVSS 6,3Эксплойта нетEPSS 1 %bluetooth · bluetooth core19 мая 2020 г.
- CVE-2020-1013522Наблюдать
Bluetooth devices supporting BR/EDR v5.2 and earlier are vulnerable to impersonation attacks
СредняяCVSS 5,4Proof of conceptEPSS 2 %bluetooth · bluetooth core19 мая 2020 г.
- CVE-2020-2655521Наблюдать
Bluetooth legacy BR/EDR PIN code pairing in Bluetooth Core Specification 1.0B through 5.2 may permit an unauthenticated nearby device to spo
СредняяCVSS 5,4Эксплойта нетEPSS 1 %bluetooth · bluetooth core specification24 мая 2021 г.
- CVE-2021-3161521Наблюдать
Unencrypted Bluetooth Low Energy baseband links in Bluetooth Core Specifications 4.0 through 5.2 may permit an adjacent device to inject a c
СредняяCVSS 5,3Эксплойта нетEPSS 0 %bluetooth · bluetooth core specification25 июн. 2021 г.
- CVE-2022-2469517Наблюдать
Bluetooth Classic in Bluetooth Core Specification through 5.3 does not properly conceal device information for Bluetooth transceivers in Non
СредняяCVSS 4,3Эксплойта нетEPSS 0 %bluetooth · bluetooth core specification2 июн. 2023 г.
- CVE-2020-3547317Наблюдать
An information leakage vulnerability in the Bluetooth Low Energy advertisement scan response in Bluetooth Core Specifications 4.0 through 5.
СредняяCVSS 4,3Эксплойта нетEPSS 0 %bluetooth · bluetooth core specification8 нояб. 2022 г.
- CVE-2020-2655816Наблюдать
Bluetooth LE and BR/EDR secure pairing in Bluetooth Core Specification 2.1 through 5.2 may permit a nearby man-in-the-middle attacker to ide
СредняяCVSS 4,2Эксплойта нетEPSS 1 %bluetooth · bluetooth core specification24 мая 2021 г.