cbcvebase.
CVE-2018-16270
published 2020-01-22

CVE-2018-16270: Samsung Galaxy Gear series before build RE2 includes the hcidump utility with no privilege or permission restriction. This allows an unprivileged process to…

PriorityP339high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
1.16%
63.4th percentile
Samsung Galaxy Gear series before build RE2 includes the hcidump utility with no privilege or permission restriction. This allows an unprivileged process to dump Bluetooth HCI packets to an arbitrary file path.

Affected

10 ranges
VendorProductVersion rangeFixed in
samsunggalaxy_gear_firmware< re2re2
samsunggear_2_firmware< re2re2
samsunggear_fit_2_firmware< re2re2
samsunggear_fit_2_pro_firmware< re2re2
samsunggear_fit_firmware< re2re2
samsunggear_live_firmware< re2re2
samsunggear_s2_firmware< re2re2
samsunggear_s3_firmware< re2re2
samsunggear_s_firmware< re2re2
samsunggear_sport_firmware< re2re2

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.