cbcvebase.
CVE-2023-2002
published 2023-05-26

CVE-2023-2002: A vulnerability was found in the HCI sockets implementation due to a missing capability check in net/bluetooth/hci_sock.c in the Linux Kernel. This flaw allows…

PriorityP433medium6.8CVSS 3.1
AVAACLPRLUINSUCLILAH
EPSS
1.47%
71.2th percentile
A vulnerability was found in the HCI sockets implementation due to a missing capability check in net/bluetooth/hci_sock.c in the Linux Kernel. This flaw allows an attacker to unauthorized execution of management commands, compromising the confidentiality, integrity, and availability of Bluetooth communication.

Affected

15 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debianlinux< linux 6.1.27-1 (bookworm)linux 6.1.27-1 (bookworm)
linuxlinux_kernel< 6.46.4
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.191-15.10.191-1
linuxlinux_kernel>= 0 < 6.1.27-16.1.27-1
linuxlinux_kernel>= 0 < 6.1.27-16.1.27-1
linuxlinux_kernel>= 0 < 6.1.27-16.1.27-1
linuxlinux_kernel>= 0 < 5.4.0-162.1795.4.0-162.179
linuxlinux_kernel>= 0 < 5.15.0-79.865.15.0-79.86
linuxlinux_kernel>= 0 < 4.15.0-223.2354.15.0-223.235
msrccbl2_kernel_5.15.116.1-2_on_cbl_mariner_2.0
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64

CVSS provenance

nvdv3.16.8MEDIUMCVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H
osv7.1HIGH
vendor_ubuntu7.1HIGH
vendor_debian6.8MEDIUM
vendor_msrc6.8MEDIUM
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.