MEDIUM · 4.3

CVE-2024-27867

An authentication issue was addressed with improved state management. This issue is fixed in AirPods Firmware Update 6A326, AirPods Firmware Update 6F8, and Beats Firmware Update 6F8. When your headph...

Vulnerability Description

An authentication issue was addressed with improved state management. This issue is fixed in AirPods Firmware Update 6A326, AirPods Firmware Update 6F8, and Beats Firmware Update 6F8. When your headphones are seeking a connection request to one of your previously paired devices, an attacker in Bluetooth range might be able to spoof the intended source device and gain access to your headphones.

CVSS Score

4.3

MEDIUM

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
LOW
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
AppleAirpods Firmware< 6a326
AppleAirpods-
ApplePowerbeats Firmware< 6f8
ApplePowerbeats-
AppleAirpods Pro Firmware< 6f8
AppleAirpods Pro-
AppleBeats Fit Pro Firmware< 6f8
AppleBeats Fit Pro-
AppleAirpods Max Firmware< 6f8
AppleAirpods Max-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2024-27867?

CVE-2024-27867 is a vulnerability with a CVSS score of 4.3 (MEDIUM). An authentication issue was addressed with improved state management. This issue is fixed in AirPods Firmware Update 6A326, AirPods Firmware Update 6F8, and Beats Firmware Update 6F8. When your headph...

How severe is CVE-2024-27867?

CVE-2024-27867 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2024-27867?

Check the references section above for vendor advisories and patch information. Affected products include: Apple Airpods Firmware, Apple Airpods, Apple Powerbeats Firmware, Apple Powerbeats, Apple Airpods Pro Firmware.