HIGH · 7.5

CVE-2018-16270

Samsung Galaxy Gear series before build RE2 includes the hcidump utility with no privilege or permission restriction. This allows an unprivileged process to dump Bluetooth HCI packets to an arbitrary ...

Vulnerability Description

Samsung Galaxy Gear series before build RE2 includes the hcidump utility with no privilege or permission restriction. This allows an unprivileged process to dump Bluetooth HCI packets to an arbitrary file path.

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
HIGH
Availability
NONE

Affected Products

VendorProductVersions
SamsungGalaxy Gear Firmware< re2
SamsungGalaxy Gear-
SamsungGear 2 Firmware< re2
SamsungGear 2-
SamsungGear Live Firmware< re2
SamsungGear Live-
SamsungGear S Firmware< re2
SamsungGear S-
SamsungGear S2 Firmware< re2
SamsungGear S2-
SamsungGear S3 Firmware< re2
SamsungGear S3-
SamsungGear Sport Firmware< re2
SamsungGear Sport-
SamsungGear Fit Firmware< re2
SamsungGear Fit-
SamsungGear Fit 2 Firmware< re2
SamsungGear Fit 2-
SamsungGear Fit 2 Pro Firmware< re2
SamsungGear Fit 2 Pro-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2018-16270?

CVE-2018-16270 is a vulnerability with a CVSS score of 7.5 (HIGH). Samsung Galaxy Gear series before build RE2 includes the hcidump utility with no privilege or permission restriction. This allows an unprivileged process to dump Bluetooth HCI packets to an arbitrary ...

How severe is CVE-2018-16270?

CVE-2018-16270 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2018-16270?

Check the references section above for vendor advisories and patch information. Affected products include: Samsung Galaxy Gear Firmware, Samsung Galaxy Gear, Samsung Gear 2 Firmware, Samsung Gear 2, Samsung Gear Live Firmware.