CVE-2018-10910

A bug in Bluez may allow for the Bluetooth Discoverable state being set to on when no Bluetooth agent is registered with the system. This situation could lead to the unauthorized pairing of certain Bluetooth devices without any form of authentication. Versions before bluez 5.51 are vulnerable.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.5 MEDIUM
LOCAL
HIGH
NONE
CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 18%
Affected Products (NVD)
VendorProductVersion
bluezbluez
𝑥
< 5.51
canonicalubuntu_linux
18.04
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
bluez
bookworm
5.66-1+deb12u2
fixed
bookworm (security)
5.66-1+deb12u1
fixed
bullseye
5.55-3.1+deb11u1
fixed
bullseye (security)
5.55-3.1+deb11u2
fixed
buster
ignored
jessie
no-dsa
sid
5.77-1
fixed
stretch
ignored
trixie
5.77-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
bluez
bionic
ignored
cosmic
ignored
disco
ignored
eoan
ignored
trusty
dne
xenial
ignored
gnome-bluetooth
bionic
Fixed 3.28.0-2ubuntu0.1
released
cosmic
not-affected
disco
not-affected
eoan
not-affected
trusty
dne
xenial
not-affected
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
bluez
RHEL 7
0:5.44-6.el7
fixed
RHEL 8
0:5.50-3.el8
fixed
bluez-cups
RHEL 7
0:5.44-6.el7
fixed
RHEL 8
0:5.50-3.el8
fixed
bluez-hid2hci
RHEL 7
0:5.44-6.el7
fixed
RHEL 8
0:5.50-3.el8
fixed
bluez-libs
RHEL 7
0:5.44-6.el7
fixed
RHEL 8
0:5.50-3.el8
fixed
bluez-libs-devel
RHEL 7
0:5.44-6.el7
fixed
RHEL 8
0:5.50-3.el8
fixed
bluez-obexd
RHEL 8
0:5.50-3.el8
fixed