CVE-2023-24023Channel Accessible by Non-Endpoint in Packages Modules Bluetooth

Severity
6.8MEDIUMNVD
EPSS
0.2%
top 57.58%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 28
Latest updateSep 1

Description

Bluetooth BR/EDR devices with Secure Simple Pairing and Secure Connections pairing in Bluetooth Core Specification 4.2 through 5.4 allow certain man-in-the-middle attacks that force a short key length, and might lead to discovery of the encryption key and live injection, aka BLUFFS.

CVSS vector

CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:NExploitability: 1.6 | Impact: 5.2

Affected Packages10 packages

Androidplatform/packages_modules_bluetooth16-next:016-next:2025-09-01+3
NVDmicrosoft/windows< 10.0.17763.5122+2
NVDmicrosoft/windows_10_1809< 10.0.17763.5122
NVDmicrosoft/windows_10_21h2< 10.0.19043.3693

🔴Vulnerability Details

7
OSV
CVE-2023-24023: In multiple locations, there is a possible way to impersonate and MitM a device across session by only compromising one session key due to an insecure2025-09-01
OSV
linux-azure, linux-lowlatency, linux-nvidia vulnerabilities2024-04-23
OSV
linux, linux-aws, linux-aws-5.15, linux-azure-5.15, linux-azure-fde, linux-azure-fde-5.15, linux-gcp, linux-gcp-5.15, linux-gke, linux-gkeop, linux-gkeop-5.15, linux-hwe-5.15, linux-ibm, linux-ibm-5.12024-04-19
OSV
linux, linux-aws, linux-aws-5.4, linux-azure, linux-azure-5.4, linux-bluefield, linux-gcp, linux-gcp-5.4, linux-gkeop, linux-hwe-5.4, linux-ibm, linux-ibm-5.4, linux-iot, linux-kvm, linux-oracle, linu2024-04-19
OSV
CVE-2023-24023: Bluetooth BR/EDR devices with Secure Simple Pairing and Secure Connections pairing in Bluetooth Core Specification 42023-11-28

📋Vendor Advisories

9
Android
CVE-2023-24023: Android Security Bulletin 2025-09-01 CVE: CVE-2023-24023 Severity: HIGH Type: EoP Affected AOSP versions: 13, 14, 15 References: A-2556019342025-09-01
Ubuntu
Linux kernel vulnerabilities2024-04-23
Ubuntu
Linux kernel vulnerabilities2024-04-19
Ubuntu
Linux kernel vulnerabilities2024-04-19
Ubuntu
Linux kernel vulnerabilities2024-04-19

💬Community

1
Bugzilla
CVE-2023-24023 kernel: Bluetooth Forward and Future Secrecy Attacks and Defenses2023-12-18
CVE-2023-24023 — Channel Accessible by Non-Endpoint | cvebase