CVE-2017-0785
published 2017-09-14CVE-2017-0785: A information disclosure vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0…
PriorityP340medium6.5CVSS 3.0
AVAACLPRNUINSUCHINAN
EXPLOIT
EPSS
12.39%
95.8th percentile
A information disclosure vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-63146698.
Affected
40 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.03.3LOWAV:A/AC:L/Au:N/C:P/I:N/A:N
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Android
CVE-2017-0785: Android Security Bulletin 2017-09-01
CVE: CVE-2017-0785
Severity: MEDIUM
Type: ID
Affected AOSP versions: 4
vendor_android·2017-09-01·CVSS 6.5
CVE-2017-0785 [MEDIUM] CVE-2017-0785: Android Security Bulletin 2017-09-01
CVE: CVE-2017-0785
Severity: MEDIUM
Type: ID
Affected AOSP versions: 4
Android Security Bulletin 2017-09-01
CVE: CVE-2017-0785
Severity: MEDIUM
Type: ID
Affected AOSP versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0
References: A-63146698
GHSA
GHSA-9hhw-5pj2-j8w2: A information disclosure vulnerability in the Android system (bluetooth)
ghsa_unreviewed·2022-05-14
CVE-2017-0785 [MEDIUM] CWE-200 GHSA-9hhw-5pj2-j8w2: A information disclosure vulnerability in the Android system (bluetooth)
A information disclosure vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-63146698.
No detection rules found.
Fortinet
BlueBorne May Affect Billions of Bluetooth Devices
blogs_fortinet·2017-09-14·CVSS 8.8
[HIGH] BlueBorne May Affect Billions of Bluetooth Devices
FORTIGUARD LABS THREAT RESEARCH
BlueBorne May Affect Billions of Bluetooth Devices
By Aamir Lakhani | September 14, 2017
Bluetooth is one of the most widely deployed and used connectivity protocols in the world. Everything from electronic devices to smartphones uses it, as do a growing number of IoT devices. Now, a new Bluetooth exploit, known as BlueBorne, exploits a number of Bluetooth vulnerabilities, making literally billions of devices potentially vulnerable to attack.
BlueBorne is a hybrid Trojan-Worm malware that spreads via Bluetooth. Because it includes worm-like properties, any infected system is also a potential carrier, and will actively search for vulnerable hosts. Unfortunately, vulnerable hosts can include any Bluetooth-enabled device, including Android, iOS, Mac OSX, a
arXiv
Threat Modelling in Internet of Things (IoT) Environment Using Dynamic Attack Graphs
arxiv_fulltext·2024-02-05
Threat Modelling in Internet of Things (IoT) Environment Using Dynamic Attack Graphs
IEEEexample:BSTcontrol
Threat Modelling in Internet of Things (IoT) Environment Using Dynamic Attack Graphs
Marwa Salayma, Member, IEEE\ of Computing, Imperial College London
London, United Kingdom
This work was supported by PETRAS National Centre of Excellence for IoT Systems Cybersecurity (PETRAS 2), Grant number is EP/S035362/1.
## Abstract
This work presents a threat modelling approach to represent changes to the attack paths through an Internet of Things (IoT) environment when the environment changes dynamically, i.e., when new devices are added or removed from the system or when whole sub-systems join or leave. The proposed approach investigates the propagation of threats using attack graphs. However, traditional attack graph approaches have been applied in static environments tha
http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.htmlhttp://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.htmlhttp://www.securityfocus.com/bid/100812http://www.securitytracker.com/id/1041300https://source.android.com/security/bulletin/2017-09-01http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.htmlhttp://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.htmlhttp://www.securityfocus.com/bid/100812http://www.securitytracker.com/id/1041300https://source.android.com/security/bulletin/2017-09-01
2017-09-14
Published