MEDIUM · 6.5

CVE-2023-21647

Information disclosure in Bluetooth when an GATT packet is received due to improper input validation.

Vulnerability Description

Information disclosure in Bluetooth when an GATT packet is received due to improper input validation.

CVSS Score

6.5

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
QualcommQca6390 Firmware-
QualcommQca6390-
QualcommQca6391 Firmware-
QualcommQca6391-
QualcommQca6426 Firmware-
QualcommQca6426-
QualcommQca6436 Firmware-
QualcommQca6436-
QualcommQca6574Au Firmware-
QualcommQca6574Au-
QualcommQca6595Au Firmware-
QualcommQca6595Au-
QualcommQca6696 Firmware-
QualcommQca6696-
QualcommQcc5100 Firmware-
QualcommQcc5100-
QualcommQcn9074 Firmware-
QualcommQcn9074-
QualcommQcs410 Firmware-
QualcommQcs410-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2023-21647?

CVE-2023-21647 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Information disclosure in Bluetooth when an GATT packet is received due to improper input validation.

How severe is CVE-2023-21647?

CVE-2023-21647 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2023-21647?

Check the references section above for vendor advisories and patch information. Affected products include: Qualcomm Qca6390 Firmware, Qualcomm Qca6390, Qualcomm Qca6391 Firmware, Qualcomm Qca6391, Qualcomm Qca6426 Firmware.