CVE-2018-5383
Bluetooth firmware or operating system software drivers in macOS versions before 10.13, High Sierra and iOS versions before 11.4, and Android versions before the 2018-06-05 patch may not sufficiently validate elliptic curve parameters used to generate…
Does this matter?
Lower severity and a low EPSS score (0.81%). Track it; it rarely justifies an emergency change on its own.
Description
Bluetooth firmware or operating system software drivers in macOS versions before 10.13, High Sierra and iOS versions before 11.4, and Android versions before the 2018-06-05 patch may not sufficiently validate elliptic curve parameters used to generate public keys during a Diffie-Hellman key exchange, which may allow a remote attacker to obtain the encryption key used by the device.
- CVSS 3.1
- 6.8 MEDIUMCVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
- EPSS
- 0.81% probability · 55th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-325, CWE-347
- Affected
- ti/wl18xx bluetooth service pack · google/android · apple/iphone os · apple/mac os x
- Source
- cret@cert.org
References
- http://www.cs.technion.ac.il/~biham/BT/Mitigation, Third Party Advisory
- http://www.securityfocus.com/bid/104879Broken Link, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1041432Broken Link, Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2019:2169Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/04/msg00005.htmlMailing List
- https://usn.ubuntu.com/4094-1/Third Party Advisory
- https://usn.ubuntu.com/4095-1/Third Party Advisory
- https://usn.ubuntu.com/4095-2/Third Party Advisory
- https://usn.ubuntu.com/4118-1/Third Party Advisory
- https://usn.ubuntu.com/4351-1/Third Party Advisory
- https://www.bluetooth.com/news/unknown/2018/07/bluetooth-sig-security-updateBroken Link, Vendor Advisory
- https://www.kb.cert.org/vuls/id/304725Third Party Advisory
- http://www.cs.technion.ac.il/~biham/BT/Mitigation, Third Party Advisory
- http://www.securityfocus.com/bid/104879Broken Link, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1041432Broken Link, Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2019:2169Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/04/msg00005.htmlMailing List
- https://usn.ubuntu.com/4094-1/Third Party Advisory
- https://usn.ubuntu.com/4095-1/Third Party Advisory
- https://usn.ubuntu.com/4095-2/Third Party Advisory
- https://usn.ubuntu.com/4118-1/Third Party Advisory
- https://usn.ubuntu.com/4351-1/Third Party Advisory
- https://www.bluetooth.com/news/unknown/2018/07/bluetooth-sig-security-updateBroken Link, Vendor Advisory
- https://www.kb.cert.org/vuls/id/304725Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.