CVE-2020-0556
published 2020-03-12CVE-2020-0556: Improper access control in subsystem for BlueZ before version 5.54 may allow an unauthenticated user to potentially enable escalation of privilege and denial…
PriorityP426high7.1CVSS 3.1
AVAACLPRNUINSCCLILAL
EPSS
1.03%
59.8th percentile
Improper access control in subsystem for BlueZ before version 5.54 may allow an unauthenticated user to potentially enable escalation of privilege and denial of service via adjacent access
Affected
44 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ipados | < 17.2 | 17.2 |
| apple | iphone_os | < 17.2 | 17.2 |
| apple | iphone_os | — | — |
| apple | macos | — | — |
| apple | macos | — | — |
| apple | macos | >= 14.0 < 14.2 | 14.2 |
| bluez | bluez | < 5.54 | 5.54 |
| bluez | bluez | >= 0 < 5.55-3.1+deb11u1 | 5.55-3.1+deb11u1 |
| bluez | bluez | >= 0 < 5.50-1.1 | 5.50-1.1 |
| bluez | bluez | >= 0 < 5.66-1+deb12u1 | 5.66-1+deb12u1 |
| bluez | bluez | >= 0 < 5.50-1.1 | 5.50-1.1 |
| bluez | bluez | >= 0 < 5.70-1.1 | 5.70-1.1 |
| bluez | bluez | >= 0 < 5.50-1.1 | 5.50-1.1 |
| bluez | bluez | >= 0 < 5.70-1.1 | 5.70-1.1 |
| bluez | bluez | >= 0 < 5.50-1.1 | 5.50-1.1 |
| bluez | bluez | >= 0 < 5.37-0ubuntu5.3 | 5.37-0ubuntu5.3 |
| bluez | bluez | >= 0 < 5.48-0ubuntu3.4 | 5.48-0ubuntu3.4 |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | bluez | < bluez 5.66-1+deb12u1 (bookworm) | bluez 5.66-1+deb12u1 (bookworm) |
| debian | bluez | < bluez 5.50-1.1 (bookworm) | bluez 5.50-1.1 (bookworm) |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L
nvdv2.05.8MEDIUMAV:A/AC:L/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
vendor_msrc6.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate and establish an encrypted connection and accept HID keyboard reports potentially permitting injection
vendor_msrc·2023-12-12·CVSS 6.3
CVE-2023-45866 [HIGH] CWE-287 Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate and establish an encrypted connection and accept HID keyboard reports potentially permitting injection
Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate and establish an encrypted connection and accept HID keyboard reports potentially permitting injection of HID messages when no user interaction has occurred in the Central role to authorize such access. An example affected package is bluez 5.64-0ubuntu1 in Ubuntu 22.04LTS. NOTE: in some cases a CVE-2020-0556 mitigation would have already addressed this Bluetooth HID Hosts issue.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of
Red Hat
bluez: unauthorized HID device connections allows keystroke injection and arbitrary commands execution
vendor_redhat·2023-12-07·CVSS 7.1
CVE-2023-45866 [HIGH] CWE-287 bluez: unauthorized HID device connections allows keystroke injection and arbitrary commands execution
bluez: unauthorized HID device connections allows keystroke injection and arbitrary commands execution
Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate and establish an encrypted connection, and accept HID keyboard reports, potentially permitting injection of HID messages when no user interaction has occurred in the Central role to authorize such access. An example affected package is bluez 5.64-0ubuntu1 in Ubuntu 22.04LTS. NOTE: in some cases, a CVE-2020-0556 mitigation would have already addressed this Bluetooth HID Hosts issue.
A flaw was found in the HID Profile in BlueZ that opens doors for unauthorized connections, especially by devices like keyboards, to inject keystrokes without user confirmation. BlueZ lacks proper restrictions on
Debian
CVE-2023-45866: bluez - Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID D...
vendor_debian·2023·CVSS 7.1
CVE-2023-45866 [HIGH] CVE-2023-45866: bluez - Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID D...
Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate and establish an encrypted connection, and accept HID keyboard reports, potentially permitting injection of HID messages when no user interaction has occurred in the Central role to authorize such access. An example affected package is bluez 5.64-0ubuntu1 in Ubuntu 22.04LTS. NOTE: in some cases, a CVE-2020-0556 mitigation would have already addressed this Bluetooth HID Hosts issue.
Scope: local
bookworm: resolved (fixed in 5.66-1+deb12u1)
bullseye: resolved (fixed in 5.55-3.1+deb11u1)
forky: resolved (fixed in 5.70-1.1)
sid: resolved (fixed in 5.70-1.1)
trixie: resolved (fixed in 5.70-1.1)
Ubuntu
BlueZ vulnerabilities
vendor_ubuntu·2020-03-30·CVSS 7.8
CVE-2016-7837 [HIGH] BlueZ vulnerabilities
Title: BlueZ vulnerabilities
Summary: Several security issues were fixed in BlueZ.
It was discovered that BlueZ incorrectly handled bonding HID and HOGP
devices. A local attacker could possibly use this issue to impersonate
non-bonded devices. (CVE-2020-0556)
It was discovered that BlueZ incorrectly handled certain commands. A local
attacker could use this issue to cause BlueZ to crash, resulting in a
denial of service, or possibly execute arbitrary code. This issue only
affected Ubuntu 16.04 LTS. (CVE-2016-7837)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
bluez: Improper access control in subsystem could result in privilege escalation and DoS
vendor_redhat·2020-03-10·CVSS 7.1
CVE-2020-0556 [HIGH] CWE-400 bluez: Improper access control in subsystem could result in privilege escalation and DoS
bluez: Improper access control in subsystem could result in privilege escalation and DoS
Improper access control in subsystem for BlueZ before version 5.54 may allow an unauthenticated user to potentially enable escalation of privilege and denial of service via adjacent access
Mitigation: Disable Bluetooth. Instructions on disabling bluetooth in Red Hat Enterprise Linux are available at: https://access.redhat.com/solutions/2682931
Package: bluez (Red Hat Enterprise Linux 6) - Not affected
Debian
CVE-2020-0556: bluez - Improper access control in subsystem for BlueZ before version 5.54 may allow an ...
vendor_debian·2020·CVSS 7.1
CVE-2020-0556 [HIGH] CVE-2020-0556: bluez - Improper access control in subsystem for BlueZ before version 5.54 may allow an ...
Improper access control in subsystem for BlueZ before version 5.54 may allow an unauthenticated user to potentially enable escalation of privilege and denial of service via adjacent access
Scope: local
bookworm: resolved (fixed in 5.50-1.1)
bullseye: resolved (fixed in 5.50-1.1)
forky: resolved (fixed in 5.50-1.1)
sid: resolved (fixed in 5.50-1.1)
trixie: resolved (fixed in 5.50-1.1)
OSV
CVE-2023-45866: Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate and establish an encrypted connection, and accept HI
osv·2023-12-08·CVSS 7.1
CVE-2023-45866 [HIGH] CVE-2023-45866: Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate and establish an encrypted connection, and accept HI
Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate and establish an encrypted connection, and accept HID keyboard reports, potentially permitting injection of HID messages when no user interaction has occurred in the Central role to authorize such access. An example affected package is bluez 5.64-0ubuntu1 in Ubuntu 22.04LTS. NOTE: in some cases, a CVE-2020-0556 mitigation would have already addressed this Bluetooth HID Hosts issue.
GHSA
GHSA-qjcj-xg77-6c32: Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate and establish an encrypted connection, and accept HI
ghsa_unreviewed·2023-12-08·CVSS 7.1
CVE-2023-45866 [HIGH] CWE-287 GHSA-qjcj-xg77-6c32: Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate and establish an encrypted connection, and accept HI
Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate and establish an encrypted connection, and accept HID keyboard reports, potentially permitting injection of HID messages when no user interaction has occurred in the Central role to authorize such access. An example affected package is bluez 5.64-0ubuntu1 in Ubuntu 22.04LTS. NOTE: in some cases, a CVE-2020-0556 mitigation would have already addressed this Bluetooth HID Hosts issue.
GHSA
GHSA-xjj6-3w9q-h5xv: Improper access control in subsystem for BlueZ before version 5
ghsa_unreviewed·2022-05-24
CVE-2020-0556 [MEDIUM] CWE-269 GHSA-xjj6-3w9q-h5xv: Improper access control in subsystem for BlueZ before version 5
Improper access control in subsystem for BlueZ before version 5.53 may allow an unauthenticated user to potentially enable escalation of privilege and denial of service via adjacent access.
OSV
bluez vulnerabilities
osv·2020-03-30·CVSS 7.8
CVE-2020-0556 [HIGH] bluez vulnerabilities
bluez vulnerabilities
It was discovered that BlueZ incorrectly handled bonding HID and HOGP
devices. A local attacker could possibly use this issue to impersonate
non-bonded devices. (CVE-2020-0556)
It was discovered that BlueZ incorrectly handled certain commands. A local
attacker could use this issue to cause BlueZ to crash, resulting in a
denial of service, or possibly execute arbitrary code. This issue only
affected Ubuntu 16.04 LTS. (CVE-2016-7837)
OSV
CVE-2020-0556: Improper access control in subsystem for BlueZ before version 5
osv·2020-03-12·CVSS 7.1
CVE-2020-0556 [HIGH] CVE-2020-0556: Improper access control in subsystem for BlueZ before version 5
Improper access control in subsystem for BlueZ before version 5.54 may allow an unauthenticated user to potentially enable escalation of privilege and denial of service via adjacent access
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-0556 bluez: Improper access control in subsystem could result in privilege escalation and DoS [fedora-all]
bugzilla·2020-03-17·CVSS 7.1
CVE-2020-0556 [HIGH] CVE-2020-0556 bluez: Improper access control in subsystem could result in privilege escalation and DoS [fedora-all]
CVE-2020-0556 bluez: Improper access control in subsystem could result in privilege escalation and DoS [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this iss
Bugzilla
CVE-2020-0556 bluez: Improper access control in subsystem could result in privilege escalation and DoS
bugzilla·2020-03-17·CVSS 7.1
CVE-2020-0556 [HIGH] CVE-2020-0556 bluez: Improper access control in subsystem could result in privilege escalation and DoS
CVE-2020-0556 bluez: Improper access control in subsystem could result in privilege escalation and DoS
Improper access control in subsystem could allow unauthenticated user to enable escalation of privilege and denial of service via adjacent access.
Upstream Reference:
https://patchwork.kernel.org/patch/11428317/
Upstream Reference:
https://patchwork.kernel.org/patch/11428319/
Discussion:
Created bluez tracking bugs for this issue:
Affects: fedora-all [bug 1814294]
---
External References:
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00352.html
---
Upstream patches:
https://git.kernel.org/pub/scm/bluetooth/bluez.git/commit/?h=5.54&id=3cccdbab2324086588df4ccf5f892fb3ce1f1787
https://git.kernel.org/pub/scm/bluetooth/bluez.git/commit/?h=5.54&id=8cdbd3
http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00008.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-06/msg00055.htmlhttps://lists.debian.org/debian-lts-announce/2020/06/msg00008.htmlhttps://security.gentoo.org/glsa/202003-49https://usn.ubuntu.com/4311-1/https://www.debian.org/security/2020/dsa-4647https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00352.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-04/msg00008.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-06/msg00055.htmlhttps://lists.debian.org/debian-lts-announce/2020/06/msg00008.htmlhttps://security.gentoo.org/glsa/202003-49https://usn.ubuntu.com/4311-1/https://www.debian.org/security/2020/dsa-4647https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00352.html
2020-03-12
Published