ZeroHour

CVE-2019-9506

CVSS 3.1
8.1 high
EPSS
3%p85
Published
()
Modified
Description

The Bluetooth BR/EDR specification up to and including version 5.1 permits sufficiently low encryption key length and does not prevent an attacker from influencing the key length negotiation. This allows practical brute-force attacks (aka "KNOB") that can decrypt traffic and inject arbitrary ciphertext without the victim noticing.

Vendors
googleapplecanonicaldebianopensuseredhathuawei
Products
android, iphone os, mac os x, tvos, watchos, ubuntu linux, debian linux, leap, mrg realtime, virtualization host eus, enterprise linux, enterprise linux aus
Weakness
CWE-310, CWE-327
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news