CVE-2018-10910

EUVD-2018-2966
A bug in Bluez may allow for the Bluetooth Discoverable state being set to on when no Bluetooth agent is registered with the system. This situation could lead to the unauthorized pairing of certain Bluetooth devices without any form of authentication. Versions before bluez 5.51 are vulnerable.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.5 MEDIUM
LOCAL
HIGH
NONE
CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L
redhatCNA
4.5 MEDIUM
LOCAL
HIGH
NONE
CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 17%
Affected Products (NVD)
VendorProductVersion
bluezbluez
𝑥
< 5.51
canonicalubuntu_linux
18.04
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
bluez
bookworm
5.66-1+deb12u2
fixed
bookworm (security)
5.66-1+deb12u1
fixed
bullseye
5.55-3.1+deb11u1
fixed
bullseye (security)
5.55-3.1+deb11u2
fixed
buster
ignored
jessie
no-dsa
sid
5.77-1
fixed
stretch
ignored
trixie
5.77-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
bluez
bionic
ignored
cosmic
ignored
disco
ignored
eoan
ignored
trusty
dne
xenial
ignored
gnome-bluetooth
bionic
Fixed 3.28.0-2ubuntu0.1
released
cosmic
not-affected
disco
not-affected
eoan
not-affected
trusty
dne
xenial
not-affected