SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2018-5383

Bluetooth firmware or operating system software drivers in macOS versions before 10.13, High Sierra and iOS versions before 11.4, and Android versions before the 2018-06-05 patch may not sufficiently validate elliptic curve parameters used to generate…

MEDIUM 6.8EPSS 0.81%

Does this matter?

Lower severity and a low EPSS score (0.81%). Track it; it rarely justifies an emergency change on its own.

Description

Bluetooth firmware or operating system software drivers in macOS versions before 10.13, High Sierra and iOS versions before 11.4, and Android versions before the 2018-06-05 patch may not sufficiently validate elliptic curve parameters used to generate public keys during a Diffie-Hellman key exchange, which may allow a remote attacker to obtain the encryption key used by the device.

CVSS 3.1
6.8 MEDIUMCVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
EPSS
0.81% probability · 55th percentile
CISA KEV
Not listed
Weakness
CWE-325, CWE-347
Affected
ti/wl18xx bluetooth service pack · google/android · apple/iphone os · apple/mac os x
Source
cret@cert.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.