Vulnerabilities in Bluetooth
3 resultsVexday analysis
A stack Bluetooth apresenta apenas 3 vulnerabilidades conhecidas na base, nenhuma delas sob ataque ativo ou crítica. O risco é baixo e estável: não há descobertas recentes (últimos 90 dias) e a fraqueza dominante (CWE-310: criptografia inadequada) é mitigável através de atualizações convencionais. O monitoramento pode ser reduzido a ciclos normais de manutenção.
CVE-2019-9506HIGHBlutooth BR/EDR specification does not specify sufficient encryption key length and allows an attacker to influence key length negotiationEPSS 2.7%CVE-2020-10135MEDIUMBluetooth devices supporting BR/EDR v5.2 and earlier are vulnerable to impersonation attacksEPSS 2.4%CVE-2020-10134MEDIUMBluetooth devices supporting LE and specific BR/EDR implementations are vulnerable to method confusion attacksEPSS 0.7%