CVE-2006-0797
Nokia N70 cell phone allows remote attackers to cause a denial of service (reboot or shutdown) through a wireless Bluetooth connection via a malformed Logical Link Control and Adaptation Protocol (L2CAP) packet whose length field is less than the actual…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (4.61%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Nokia N70 cell phone allows remote attackers to cause a denial of service (reboot or shutdown) through a wireless Bluetooth connection via a malformed Logical Link Control and Adaptation Protocol (L2CAP) packet whose length field is less than the actual length of the packet, possibly triggering a buffer overflow, as demonstrated using the Bluetooth Stack Smasher (BSS).
- CVSS 2.0
- 7.8 HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
- EPSS
- 4.61% probability · 91th percentile
- CISA KEV
- Not listed
- Affected
- nokia/n70
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/fulldisclosure/2006-02/0316.htmlExploit, Vendor Advisory
- http://secunia.com/advisories/18724
- http://www.osvdb.org/23061Exploit
- http://www.secuobs.com/news/15022006-nokia_n70.shtml#english
- http://www.securityfocus.com/bid/16666Exploit
- http://www.vupen.com/english/advisories/2006/0538
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24688
- http://archives.neohapsis.com/archives/fulldisclosure/2006-02/0316.htmlExploit, Vendor Advisory
- http://secunia.com/advisories/18724
- http://www.osvdb.org/23061Exploit
- http://www.secuobs.com/news/15022006-nokia_n70.shtml#english
- http://www.securityfocus.com/bid/16666Exploit
- http://www.vupen.com/english/advisories/2006/0538
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24688
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.