CVE-2019-2102
published 2019-06-07CVE-2019-2102: In the Bluetooth Low Energy (BLE) specification, there is a provided example Long Term Key (LTK). If a BLE device were to use this as a hardcoded LTK, it is…
PriorityP340high8.8CVSS 3.0
AVAACLPRNUINSUCHIHAH
EPSS
0.33%
25.7th percentile
In the Bluetooth Low Energy (BLE) specification, there is a provided example Long Term Key (LTK). If a BLE device were to use this as a hardcoded LTK, it is theoretically possible for a proximate attacker to remotely inject keystrokes on a paired Android host due to improperly used crypto. User interaction is not needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Android ID: A-128843052.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | android | — | — |
| apple | ios | — | — |
| apple | macos_mojave_10.14.5_security_update_2019-003_high_sierra_security_update_2019-0 | — | — |
| apple | tvos | — | — |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.08.3HIGHAV:A/AC:L/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5jf8-vrfc-7fr9: In the Bluetooth Low Energy (BLE) specification, there is a provided example Long Term Key (LTK)
ghsa_unreviewed·2022-05-24
CVE-2019-2102 [HIGH] GHSA-5jf8-vrfc-7fr9: In the Bluetooth Low Energy (BLE) specification, there is a provided example Long Term Key (LTK)
In the Bluetooth Low Energy (BLE) specification, there is a provided example Long Term Key (LTK). If a BLE device were to use this as a hardcoded LTK, it is theoretically possible for a proximate attacker to remotely inject keystrokes on a paired Android host due to improperly used crypto. User interaction is not needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Android ID: A-128843052.
Android
CVE-2019-2102: Android Security Bulletin 2019-06-01
CVE: CVE-2019-2102
Severity: HIGH
Type: EoP
Affected AOSP versions: 7
vendor_android·2019-06-01·CVSS 8.8
CVE-2019-2102 [HIGH] CVE-2019-2102: Android Security Bulletin 2019-06-01
CVE: CVE-2019-2102
Severity: HIGH
Type: EoP
Affected AOSP versions: 7
Android Security Bulletin 2019-06-01
CVE: CVE-2019-2102
Severity: HIGH
Type: EoP
Affected AOSP versions: 7.0, 7.1.1, 7.1.2, 8.0, 8.1, 9
References: A-128843052
Apple
CVE-2019-2102: iOS 12.3
vendor_apple·2019-05-13·CVSS 8.8
CVE-2019-2102 [HIGH] CVE-2019-2102: iOS 12.3
Apple Security Update: About the security content of iOS 12.3
Product: iOS
Version: 12.3
CVE: CVE-2019-2102
Component: Bluetooth
Impact: Due to a misconfiguration in the Bluetooth pairing protocols of a Bluetooth Low Energy (BLE) version of FIDO Security Keys it may be possible for an attacker with physical proximity to be able to intercept Bluetooth traffic during pairing
Description: This issue was addressed by disabling accessories with insecure Bluetooth connections. Customers using the Bluetooth Low Energy (BLE) version of the Titan Security Key by Google should review Android’s June Bulletins and Google’s advisory and take appropriate action.
Apple
CVE-2019-2102: tvOS 12.3
vendor_apple·2019-05-13·CVSS 8.8
CVE-2019-2102 [HIGH] CVE-2019-2102: tvOS 12.3
Apple Security Update: About the security content of tvOS 12.3
Product: tvOS
Version: 12.3
CVE: CVE-2019-2102
Component: Bluetooth
Impact: Due to a misconfiguration in the Bluetooth pairing protocols of a Bluetooth Low Energy (BLE) version of FIDO Security Keys it may be possible for an attacker with physical proximity to be able to intercept Bluetooth traffic during pairing
Description: This issue was addressed by disabling accessories with insecure Bluetooth connections. Customers using the Bluetooth Low Energy (BLE) version of the Titan Security Key by Google should review Android’s June Bulletins and Google’s advisory and take appropriate action.
Apple
CVE-2019-2102: macOS Mojave 10.14.5, Security Update 2019-003 High Sierra, Security Update 2019-003 Sierra
vendor_apple·2019-05-13·CVSS 8.8
CVE-2019-2102 [HIGH] CVE-2019-2102: macOS Mojave 10.14.5, Security Update 2019-003 High Sierra, Security Update 2019-003 Sierra
Apple Security Update: About the security content of macOS Mojave 10.14.5, Security Update 2019-003 High Sierra, Security Update 2019-003 Sierra
Product: macOS Mojave 10.14.5, Security Update 2019-003 High Sierra, Security Update 2019-003 Sierra
CVE: CVE-2019-2102
Component: Bluetooth
Impact: Due to a misconfiguration in the Bluetooth pairing protocols of a Bluetooth Low Energy (BLE) version of FIDO Security Keys it may be possible for an attacker with physical proximity to be able to intercept Bluetooth traffic during pairing
Description: This issue was addressed by disabling accessories with insecure Bluetooth connections. Customers using the Bluetooth Low Energy (BLE) version of the Titan Security Key by Google should review Android’s June Bulletins and Google’s advisory and take approp
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://source.android.com/security/bulletin/2019-06-01https://support.apple.com/kb/HT210118https://support.apple.com/kb/HT210119https://support.apple.com/kb/HT210120https://source.android.com/security/bulletin/2019-06-01https://support.apple.com/kb/HT210118https://support.apple.com/kb/HT210119https://support.apple.com/kb/HT210120
2019-06-07
Published