SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2006-1365

The Motorola PEBL U6, the Motorola V600, and possibly the Motorola E398 and other Motorola phones allow remote attackers to add an entry for their own Bluetooth device to a target device's list of trusted devices (aka Device History), and possibly…

MEDIUM 5.0EPSS 1.43%

Does this matter?

Lower severity and a low EPSS score (1.43%). Track it; it rarely justifies an emergency change on its own.

Description

The Motorola PEBL U6, the Motorola V600, and possibly the Motorola E398 and other Motorola phones allow remote attackers to add an entry for their own Bluetooth device to a target device's list of trusted devices (aka Device History), and possibly obtain AT level access to the target device, by initiating and interrupting an OBEX Push Profile that pretends to send a vCard, aka a "HeloMoto" attack.

CVSS 2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
EPSS
1.43% probability · 71th percentile
CISA KEV
Not listed
Affected
motorola/e398 · motorola/pebl u6 · motorola/v600
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.