[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247862

 
 

909

 
 

194603

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2019-9506Date: (C)2019-08-15   (M)2024-04-19


The Bluetooth BR/EDR specification up to and including version 5.1 permits sufficiently low encryption key length and does not prevent an attacker from influencing the key length negotiation. This allows practical brute-force attacks (aka "KNOB") that can decrypt traffic and inject arbitrary ciphertext without the victim noticing.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V3 Severity:CVSS V2 Severity:
CVSS Score : 8.1CVSS Score : 4.8
Exploit Score: 2.8Exploit Score: 6.5
Impact Score: 5.2Impact Score: 4.9
 
CVSS V3 Metrics:CVSS V2 Metrics:
Attack Vector: ADJACENT_NETWORKAccess Vector: ADJACENT_NETWORK
Attack Complexity: LOWAccess Complexity: LOW
Privileges Required: NONEAuthentication: NONE
User Interaction: NONEConfidentiality: PARTIAL
Scope: UNCHANGEDIntegrity: PARTIAL
Confidentiality: HIGHAvailability: NONE
Integrity: HIGH 
Availability: NONE 
  
Reference:
http://seclists.org/fulldisclosure/2019/Aug/11
http://seclists.org/fulldisclosure/2019/Aug/13
http://seclists.org/fulldisclosure/2019/Aug/14
http://seclists.org/fulldisclosure/2019/Aug/15
RHSA-2019:2975
RHSA-2019:3055
RHSA-2019:3076
RHSA-2019:3089
RHSA-2019:3165
RHSA-2019:3187
RHSA-2019:3217
RHSA-2019:3218
RHSA-2019:3220
RHSA-2019:3231
RHSA-2019:3309
RHSA-2019:3517
RHSA-2020:0204
USN-4115-1
USN-4118-1
USN-4147-1
VU#918987
https://lists.debian.org/debian-lts-announce/2019/09/msg00014.html
https://lists.debian.org/debian-lts-announce/2019/09/msg00015.html
https://lists.debian.org/debian-lts-announce/2019/09/msg00025.html
http://www.cs.ox.ac.uk/publications/publication12404-abstract.html
http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20190828-01-knob-en
https://www.bluetooth.com/security/statement-key-negotiation-of-bluetooth/
https://www.usenix.org/conference/usenixsecurity19/presentation/antonioli
openSUSE-SU-2019:2307
openSUSE-SU-2019:2308

CPE    26
cpe:/h:huawei:bla-tl00b:-
cpe:/h:huawei:hima-l29c:-
cpe:/h:huawei:potter-al00c:-
cpe:/h:huawei:leland-l21a:-
...
CWE    1
CWE-327
OVAL    40
oval:org.secpod.oval:def:59589
oval:org.secpod.oval:def:705229
oval:org.secpod.oval:def:57623
oval:org.secpod.oval:def:89000558
...

© SecPod Technologies