VulnerabilityModified
CVE-2017-17860
In Samsung Gear products, Bluetooth link key is updated to the different key which is same with attacker's link key.
MEDIUM 5.7EPSS 0.29%
Does this matter?
Lower severity and a low EPSS score (0.29%). Track it; it rarely justifies an emergency change on its own.
Description
In Samsung Gear products, Bluetooth link key is updated to the different key which is same with attacker's link key. It can be attacked without user's intention only if attacker can reveal the Bluetooth address of target device and paired user's smartphone
- CVSS 3.0
- 5.7 MEDIUMCVSS:3.0/AV:A/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
- EPSS
- 0.29% probability · 21th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- google/android
- Source
- cve@mitre.org
References
- https://drive.google.com/open?id=0B5L-0MoH_v7fcGljUS1SYnlkOHMExploit, Third Party Advisory
- https://drive.google.com/open?id=0B5L-0MoH_v7fcGljUS1SYnlkOHMExploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.