A vulnerability was found in the bluez, where Passkey Entry protocol used in Secure Simple Pairing (SSP), Secure Connections (SC) and LE Secure Connections (LESC) of the Bluetooth Core Specification is vulnerable to an impersonation attack where an active attacker can impersonate the initiating device without any previous knowledge.
Platform | Package | Release Date | Advisory |
---|---|---|---|
Amazon Linux 2 - Core | kernel | 2021-07-14 20:35 | ALAS2-2021-1685 |
Amazon Linux 2 - Kernel-5.10 Extra | kernel | 2022-01-20 23:37 | ALAS2KERNEL-5.10-2022-002 |
Amazon Linux 2 - Kernel-5.4 Extra | kernel | 2022-01-12 19:26 | ALAS2KERNEL-5.4-2022-004 |
Score Type | Score | Vector | |
---|---|---|---|
Amazon Linux | CVSSv3 | 4.2 | CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N |
NVD | CVSSv2 | 4.3 | AV:A/AC:M/Au:N/C:P/I:P/A:N |
NVD | CVSSv3 | 4.2 | CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N |