V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
BDU:2019-03002
BDU
High

Уязвимость реализации протокола согласования ключей шифрования Bluetooth BR/EDR связана с использованием криптографических алгоритмов, соде…

CVSS
8.1
High
EPSS
0.00
p0
Published
2019-01-01
Updated
2019-01-01
Description

Уязвимость реализации протокола согласования ключей шифрования Bluetooth BR/EDR связана с использованием криптографических алгоритмов, содержащих дефекты. Эксплуатация уязвимости может позволить нарушителю, действующему удалённо, реализовать атаку типа «человек посередине», вмешаться в процедуру настройки шифрования для соединения BR/EDR и уменьшить длину используемого ключа шифрования

Affected products
Bluetooth special interest group Bluetooth br/edrBluetooth special interest group Bluetooth br/edrBluetooth special interest group Bluetooth br/edrBluetooth special interest group Bluetooth br/edrBluetooth special interest group Bluetooth br/edrBluetooth special interest group Bluetooth br/edrBluetooth special interest group Bluetooth br/edrBluetooth special interest group Bluetooth br/edrBluetooth special interest group Bluetooth br/edrBluetooth special interest group Bluetooth br/edrBluetooth special interest group Bluetooth br/edrBluetooth special interest group Bluetooth br/edrBluetooth special interest group Bluetooth br/edrBluetooth special interest group Bluetooth br/edrBluetooth special interest group Bluetooth br/edrBluetooth special interest group Bluetooth br/edrBluetooth special interest group Bluetooth br/edrBluetooth special interest group Bluetooth br/edrBluetooth special interest group Bluetooth br/edrBluetooth special interest group Bluetooth br/edr
CVSS vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Timeline
2019-01-01
Published
2019-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: A
Adjacent Network (A)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: N
None (N)
Exploit indicators
EPSS
0.000 · p0
Known exploited (KEV)
No
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected software
ProductVendorStatus
bluetooth br/edrbluetooth special interest groupTracked
bluetooth br/edrbluetooth special interest groupTracked
bluetooth br/edrbluetooth special interest groupTracked
bluetooth br/edrbluetooth special interest groupTracked
bluetooth br/edrbluetooth special interest groupTracked
bluetooth br/edrbluetooth special interest groupTracked
bluetooth br/edrbluetooth special interest groupTracked
bluetooth br/edrbluetooth special interest groupTracked
bluetooth br/edrbluetooth special interest groupTracked
bluetooth br/edrbluetooth special interest groupTracked
bluetooth br/edrbluetooth special interest groupTracked
bluetooth br/edrbluetooth special interest groupTracked
bluetooth br/edrbluetooth special interest groupTracked
bluetooth br/edrbluetooth special interest groupTracked
bluetooth br/edrbluetooth special interest groupTracked
bluetooth br/edrbluetooth special interest groupTracked
bluetooth br/edrbluetooth special interest groupTracked
bluetooth br/edrbluetooth special interest groupTracked
bluetooth br/edrbluetooth special interest groupTracked
bluetooth br/edrbluetooth special interest groupTracked
Source databases
BDU
MSR
Related vulnerabilities
External references
https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-9506@https://bugzilla.kernel.org/show_bug.cgi?id=203997@https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9506@https://kb.cert.org/vuls/id/918987/@https://kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.133@https://kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.58@https://kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.4.185@https://kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.9.185@https://kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.1.17@https://knobattack.com/@https://nvd.nist.gov/vuln/detail/CVE-2019-9506@https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-9506@https://seclists.org/fulldisclosure/2019/Aug/11@https://seclists.org/fulldisclosure/2019/Aug/13@https://seclists.org/fulldisclosure/2019/Aug/14@https://seclists.org/fulldisclosure/2019/Aug/15@https://source.android.com/security/bulletin/2019-08-01@https://support.apple.com/ru-ru/HT210346@https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190813-bluetooth@https://ubuntu.com/security/notices/USN-4115-1@https://ubuntu.com/security/notices/USN-4118-1@https://ubuntu.com/security/notices/USN-4147-1@https://usn.ubuntu.com/usn/usn-4115-1@https://usn.ubuntu.com/usn/usn-4118-1@https://usn.ubuntu.com/usn/usn-4147-1@https://vulmon.com/vulnerabilitydetails?qid=CVE-2019-9506@https://www.bluetooth.com/security/statement-key-negotiation-of-bluetooth/@https://www.cve.org/CVERecord?id=CVE-2019-9506@https://www.usenix.org/conference/usenixsecurity19/presentation/antonioli