MEDIUM · 6.3

CVE-2023-45866

Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate and establish an encrypted connection, and accept HID keyboard reports, potentially permitting injecti...

Vulnerability Description

Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate and establish an encrypted connection, and accept HID keyboard reports, potentially permitting injection of HID messages when no user interaction has occurred in the Central role to authorize such access. An example affected package is bluez 5.64-0ubuntu1 in Ubuntu 22.04LTS. NOTE: in some cases, a CVE-2020-0556 mitigation would have already addressed this Bluetooth HID Hosts issue.

CVSS Score

6.3

MEDIUM

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
LOW
Integrity
LOW
Availability
LOW

Affected Products

VendorProductVersions
GoogleAndroid4.2.2
BluproductsDash3.5
GoogleNexus 5-
GooglePixel 2-
GooglePixel 4A-
GooglePixel 6-
GooglePixel 7-
CanonicalUbuntu Linux18.04
AppleIphone Os16.6
AppleIphone Se-
AppleMacos12.6.7
AppleMacbook Air2017
AppleMacbook Prom2
FedoraprojectFedora38
AppleIpados< 17.2
DebianDebian Linux10.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2023-45866?

CVE-2023-45866 is a vulnerability with a CVSS score of 6.3 (MEDIUM). Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate and establish an encrypted connection, and accept HID keyboard reports, potentially permitting injecti...

How severe is CVE-2023-45866?

CVE-2023-45866 has been rated MEDIUM with a CVSS base score of 6.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2023-45866?

Check the references section above for vendor advisories and patch information. Affected products include: Google Android, Bluproducts Dash, Google Nexus 5, Google Pixel 2, Google Pixel 4A.