ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

Bluetooth vulnerability allows snooping of traffic between paired devices

mediumVulnerabilityimportance 35CVE-2018-5383

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2018-5383
Bluetooth firmware or operating system software drivers in macOS versions before 10.13, High Sierra and iOS versions before 11.4, and Android versions before th

Bluetooth firmware or operating system software drivers in macOS versions before 10.13, High Sierra and iOS versions before 11.4, and Android versions before the 2018-06-05 patch may not sufficiently validate elliptic curve parameters used to generate public keys during a Diffie-Hellman key exchange, which may allow a remote attacker to obtain the encryption key used by the device.

NVD description · AI analysis pending
6.8<1%
  • ti wl18xx bluetooth service pack
  • ti android
  • ti iphone os
  • +1 more
Full article375 words · extracted from helpnetsecurity.com · click to collapse

Researchers Eli Biham and Lior Neumann have discovered a vulnerability in two Bluetooth features that could be exploited by attackers to gain a man-in-the-middle position and to monitor and fiddle with the traffic between two devices connected via that wireless technology.

Bluetooth CVE-2018-5383

“Both Bluetooth low energy (LE) implementations of Secure Connections Pairing in operating system software and BR/EDR implementations of Secure Simple Pairing in device firmware may be affected,” the Carnegie-Mellon CERT notes.

The vulnerability (CVE-2018-5383) exists because the Bluetooth specification recommends, but does not require, that a device supporting the Secure Simple Pairing or LE Secure Connections features validate the public key received over the air when pairing with a new device.

Risk and mitigation

“For an attack to be successful, an attacking device would need to be within wireless range of two vulnerable Bluetooth devices that were going through a pairing procedure. The attacking device would need to intercept the public key exchange by blocking each transmission, sending an acknowledgement to the sending device, and then injecting the malicious packet to the receiving device within a narrow time window. If only one device had the vulnerability, the attack would not be successful,” the Bluetooth Special Interest Group (SIG) explained.

“There is no evidence that the vulnerability has been exploited maliciously and the Bluetooth SIG is not aware of any devices implementing the attack having been developed, including by the researchers who identified the vulnerability. ”

The organization has updated the Bluetooth specification to require products to validate any public key received as part of public key-based security procedures, and is urging vendors to make the required changes to software (OSes and drivers) and firmware (IoT devices) to plug the security hole.

It seems that the bug affects Bluetooth implementations and operating system drivers of a number of vendors, including Apple, Broadcom, Intel and Qualcomm.

Apple has updated the documents regarding the security updates included in iOS 11.4, tvOS 11.4, watchOS 4.3.1, macOS High Sierra 10.13.5 and 10.13.6, Sierra and El Capitan (released in May and July 2018) to include the reference to the vulnerability, as it has been silently patched.

Dell has also pushed out driver updates to fix the flaw.

Microsoft has confirmed that its products aren’t affected by this vulnerability.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2018/07/24/bluetooth-cve-2018-5383/