cbcvebase.
CVE-2023-24023
published 2023-11-28

CVE-2023-24023: Bluetooth BR/EDR devices with Secure Simple Pairing and Secure Connections pairing in Bluetooth Core Specification 4.2 through 5.4 allow certain…

medium6.8CVSS 3.1
AVAACHPRNUINSUCHIHAN
Bluetooth BR/EDR devices with Secure Simple Pairing and Secure Connections pairing in Bluetooth Core Specification 4.2 through 5.4 allow certain man-in-the-middle attacks that force a short key length, and might lead to discovery of the encryption key and live injection, aka BLUFFS.

Affected

41 ranges· showing 25
VendorProductVersion rangeFixed in
bluetoothbluetooth_core_specification4.2 – 5.4
debianlinux< linux 6.1.76-1 (bookworm)linux 6.1.76-1 (bookworm)
googleandroid
linuxlinux_kernel>= 0 < 6.1.76-16.1.76-1
linuxlinux_kernel>= 0 < 6.6.9-16.6.9-1
linuxlinux_kernel>= 0 < 6.6.9-16.6.9-1
linuxlinux_kernel>= 0 < 5.4.0-177.1975.4.0-177.197
linuxlinux_kernel>= 0 < 5.15.0-105.1155.15.0-105.115
linuxlinux_kernel>= 0 < 4.4.0-253.2874.4.0-253.287
linuxlinux_kernel>= 0 < 4.15.0-224.2364.15.0-224.236
microsoftwindows_10_1809< 10.0.17763.512210.0.17763.5122
microsoftwindows_10_21h2< 10.0.19043.369310.0.19043.3693
microsoftwindows_10_22h2< 10.0.19045.369310.0.19045.3693
microsoftwindows_11_21h2< 10.0.22000.260010.0.22000.2600
microsoftwindows_11_22h2< 10.0.22621.271510.0.22621.2715
microsoftwindows_11_23h2< 10.0.22631.271510.0.22631.2715
microsoftwindows_server_2019< 10.0.17763.512210.0.17763.5122
microsoftwindows_server_2022< 10.0.20348.211310.0.20348.2113
microsoftwindows_server_2022_23h2< 10.0.25398.53110.0.25398.531
msrcwindows_10_version_1809_for_32-bit_systems
msrcwindows_10_version_1809_for_arm64-based_systems
msrcwindows_10_version_1809_for_x64-based_systems
msrcwindows_10_version_21h2_for_32-bit_systems
msrcwindows_10_version_21h2_for_arm64-based_systems
msrcwindows_10_version_21h2_for_x64-based_systems

CVSS provenance

nvdv3.16.8MEDIUMCVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
osv7.0HIGH