CVE-2023-40090Observable Discrepancy in Packages Modules Bluetooth

Severity
6.5MEDIUMNVD
EPSS
0.0%
top 94.10%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 4
Latest updateDec 5

Description

In BTM_BleVerifySignature of btm_ble.cc, there is a possible way to bypass signature validation due to side channel information disclosure. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages3 packages

Androidplatform/packages_modules_bluetooth13:013:2023-12-01+1
CVEListV5google/android5 versions+4
NVDgoogle/android5 versions+4

Patches

🔴Vulnerability Details

4
GHSA
GHSA-x74m-v58j-5gpr: In BTM_BleVerifySignature of btm_ble2023-12-05
CVEList
CVE-2023-40090: In BTM_BleVerifySignature of btm_ble2023-12-04
OSV
CVE-2023-40090: In BTM_BleVerifySignature of btm_ble2023-12-01
OSV
tiff vulnerabilities2023-11-23

📋Vendor Advisories

1
Android
CVE-2023-40090: Android Security Bulletin 2023-12-01 CVE: CVE-2023-40090 Severity: HIGH Type: EoP Affected AOSP versions: 11, 12, 12L, 13, 14 References: A-2744788072023-12-01
CVE-2023-40090 — Observable Discrepancy | cvebase