BlueZ HID over GATT Profile Improper Access Control Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of BlueZ. Authentication is not required to exploit this vulnerability. The specific flaw exists within the implementation of the HID over GATT Profile. The issue results from the lack of authorization prior to allowing access to functionality. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-25177.
History

Fri, 20 Dec 2024 18:30:00 +0000

Type Values Removed Values Added
Weaknesses NVD-CWE-noinfo
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Thu, 05 Dec 2024 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Bluez
Bluez bluez
CPEs cpe:2.3:a:bluez:bluez:5.77:*:*:*:*:*:*:*
Vendors & Products Bluez
Bluez bluez
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 22 Nov 2024 21:15:00 +0000

Type Values Removed Values Added
Description BlueZ HID over GATT Profile Improper Access Control Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of BlueZ. Authentication is not required to exploit this vulnerability. The specific flaw exists within the implementation of the HID over GATT Profile. The issue results from the lack of authorization prior to allowing access to functionality. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-25177.
Title BlueZ HID over GATT Profile Improper Access Control Remote Code Execution Vulnerability
Weaknesses CWE-284
References
Metrics cvssV3_0

{'score': 8.8, 'vector': 'CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: zdi

Published: 2024-11-22T21:02:52.231Z

Updated: 2024-12-05T14:42:11.502Z

Reserved: 2024-09-13T17:57:29.617Z

Link: CVE-2024-8805

cve-icon Vulnrichment

Updated: 2024-12-05T14:42:05.332Z

cve-icon NVD

Status : Analyzed

Published: 2024-11-22T21:15:18.660

Modified: 2024-12-20T18:05:47.173

Link: CVE-2024-8805

cve-icon Redhat

No data.