SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2017-17860

In Samsung Gear products, Bluetooth link key is updated to the different key which is same with attacker's link key.

MEDIUM 5.7EPSS 0.29%

Does this matter?

Lower severity and a low EPSS score (0.29%). Track it; it rarely justifies an emergency change on its own.

Description

In Samsung Gear products, Bluetooth link key is updated to the different key which is same with attacker's link key. It can be attacked without user's intention only if attacker can reveal the Bluetooth address of target device and paired user's smartphone

CVSS 3.0
5.7 MEDIUMCVSS:3.0/AV:A/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
EPSS
0.29% probability · 21th percentile
CISA KEV
Not listed
Weakness
CWE-20
Affected
google/android
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.