CVE-2018-10910Incorrect Authorization in Bluez

Severity
3.3LOWNVD
EPSS
0.1%
top 82.29%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 28
Latest updateMay 13

Description

A bug in Bluez may allow for the Bluetooth Discoverable state being set to on when no Bluetooth agent is registered with the system. This situation could lead to the unauthorized pairing of certain Bluetooth devices without any form of authentication. Versions before bluez 5.51 are vulnerable.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 1.8 | Impact: 1.4

Affected Packages4 packages

NVDbluez/bluez< 5.51
debiandebian/bluez< bluez 5.54-1 (bookworm)
Debianbluez/bluez< 5.54-1+3
CVEListV5the_bluez_project/bluezbefore 5.51

Also affects: Ubuntu Linux 18.04

Patches

🔴Vulnerability Details

2
GHSA
GHSA-62rf-fp64-gxpc: A bug in Bluez may allow for the Bluetooth Discoverable state being set to on when no Bluetooth agent is registered with the system2022-05-13
OSV
CVE-2018-10910: A bug in Bluez may allow for the Bluetooth Discoverable state being set to on when no Bluetooth agent is registered with the system2019-01-28

📋Vendor Advisories

3
Ubuntu
GNOME Bluetooth vulnerability2019-01-14
Red Hat
bluez: failure in disabling Bluetooth discoverability in certain cases may lead to the unauthorized pairing of Bluetooth devices2018-07-20
Debian
CVE-2018-10910: bluez - A bug in Bluez may allow for the Bluetooth Discoverable state being set to on wh...2018

💬Community

3
Bugzilla
CVE-2019-10909 CVE-2019-10910 CVE-2019-10912 CVE-2019-10913 CVE-2018-19790 CVE-2018-19789 php-symfony: Multiple vulnerabilities fixed in symfony 2.8.72019-06-12
Bugzilla
CVE-2018-10910 bluez: failure in disabling Bluetooth discoverability in certain cases may lead to the unauthorized pairing of Bluetooth devices [fedora-all]2018-07-20
Bugzilla
CVE-2018-10910 bluez: failure in disabling Bluetooth discoverability in certain cases may lead to the unauthorized pairing of Bluetooth devices2018-07-20