CVE-2016-6541
TrackR Bravo device allows unauthenticated pairing, which enables unauthenticated connected applications to write to various device attributes.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.09%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
TrackR Bravo device allows unauthenticated pairing, which enables unauthenticated connected applications to write to various device attributes. Updated apps, version 5.1.6 for iOS and 2.2.5 for Android, have been released by the vendor to address the vulnerabilities in CVE-2016-6538, CVE-2016-6539, CVE-2016-6540 and CVE-2016-6541.
- CVSS 3.0
- 8.8 HIGHCVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.09% probability · 64th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-306, CWE-287
- Affected
- thetrackr/trackr bravo firmware
- Source
- cret@cert.org
References
- http://www.securityfocus.com/bid/93874Third Party Advisory, VDB Entry
- https://blog.rapid7.com/2016/10/25/multiple-bluetooth-low-energy-ble-tracker-vulnerabilities/Third Party Advisory
- https://www.kb.cert.org/vuls/id/617567Third Party Advisory, US Government Resource
- https://www.kb.cert.org/vuls/id/TNOY-AF3KCZThird Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/93874Third Party Advisory, VDB Entry
- https://blog.rapid7.com/2016/10/25/multiple-bluetooth-low-energy-ble-tracker-vulnerabilities/Third Party Advisory
- https://www.kb.cert.org/vuls/id/617567Third Party Advisory, US Government Resource
- https://www.kb.cert.org/vuls/id/TNOY-AF3KCZThird Party Advisory, US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.