cbcvebase.

Platform System Bt vulnerabilities

66 known vulnerabilities affecting platform/system_bt.

Total CVEs
66
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
UNKNOWN66

Vulnerabilities

Page 4 of 4
CVE-2024-43763P4UNKNOWN≥ 12:0, < 12:2025-01-01≥ 12L:0, < 12L:2025-01-012025-01-01
CVE-2024-43763 CVE-2024-43763: In build_read_multi_rsp of gatt_sr In build_read_multi_rsp of gatt_sr.cc, there is a possible denial of service due to a logic error in the code. This could lead to remote (proximal/adjacent) denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2020-26555P4UNKNOWN≥ 8.1:0, < 8.1:2021-06-05≥ 9:0, < 9:2021-06-05+2 more2021-06-01
CVE-2020-26555 CVE-2020-26555: In btm_sec_pin_code_request of btm_sec In btm_sec_pin_code_request of btm_sec.cc, there is a possible bypass of Bluetooth pairing pin-code due to improperly used crypto. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2023-20952P4UNKNOWN≥ 11:0, < 11:2023-03-01≥ 12:0, < 12:2023-03-01+1 more2023-03-01
CVE-2023-20952 CVE-2023-20952: In A2DP_BuildCodecHeaderSbc of a2dp_sbc In A2DP_BuildCodecHeaderSbc of a2dp_sbc.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2020-26558P4UNKNOWN≥ 8.1:0, < 8.1:2021-06-05≥ 9:0, < 9:2021-06-05+2 more2021-06-01
CVE-2020-26558 CVE-2020-26558: In smp_process_pairing_public_key of smp_act In smp_process_pairing_public_key of smp_act.cc, there is a possible interception of Bluetooth pairing from an on-path attacker due to improperly used crypto. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2020-0379P4UNKNOWN≥ 8.0:0, < 8.0:2020-09-01≥ 8.1:0, < 8.1:2020-09-01+2 more2020-09-01
CVE-2020-0379 CVE-2020-0379: In the Bluetooth service, there is a possible spoofing attack due to a logic error In the Bluetooth service, there is a possible spoofing attack due to a logic error. This could lead to remote information disclosure of sensitive information with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2021-1007P4UNKNOWN≥ 12:0, < 12:2021-12-012021-12-01
CVE-2021-1007 CVE-2021-1007: In btu_hcif_process_event of btu_hcif In btu_hcif_process_event of btu_hcif.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.
osv
Platform System Bt vulnerabilities | cvebase