CVE-2019-9506
The Bluetooth BR/EDR specification up to and including version 5.1 permits sufficiently low encryption key length and does not prevent an attacker from influencing the key length negotiation.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.69%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The Bluetooth BR/EDR specification up to and including version 5.1 permits sufficiently low encryption key length and does not prevent an attacker from influencing the key length negotiation. This allows practical brute-force attacks (aka "KNOB") that can decrypt traffic and inject arbitrary ciphertext without the victim noticing.
- CVSS 3.1
- 8.1 HIGHCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
- EPSS
- 2.69% probability · 85th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-310, CWE-327
- Affected
- google/android · apple/iphone os · apple/mac os x · apple/tvos · apple/watchos · canonical/ubuntu linux · debian/debian linux · opensuse/leap · redhat/mrg realtime · redhat/virtualization host eus · redhat/enterprise linux · redhat/enterprise linux aus · redhat/enterprise linux eus · redhat/enterprise linux for real time · redhat/enterprise linux for real time eus · redhat/enterprise linux for real time for nfv · redhat/enterprise linux for real time for nfv eus · redhat/enterprise linux server · redhat/enterprise linux server aus · redhat/enterprise linux server tus · +40 more
- Source
- cret@cert.org
References
- http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00036.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00037.htmlMailing List, Third Party Advisory
- http://seclists.org/fulldisclosure/2019/Aug/11Mailing List, Third Party Advisory
- http://seclists.org/fulldisclosure/2019/Aug/13Mailing List, Third Party Advisory
- http://seclists.org/fulldisclosure/2019/Aug/14Mailing List, Third Party Advisory
- http://seclists.org/fulldisclosure/2019/Aug/15Mailing List, Third Party Advisory
- http://www.cs.ox.ac.uk/publications/publication12404-abstract.htmlThird Party Advisory
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20190828-01-knob-enThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2975Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3055Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3076Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3089Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3165Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3187Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3217Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3218Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3220Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3231Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3309Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3517Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0204Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/09/msg00014.htmlMailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/09/msg00015.htmlMailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/09/msg00025.htmlMailing List, Third Party Advisory
- https://usn.ubuntu.com/4115-1/Third Party Advisory
- https://usn.ubuntu.com/4118-1/Third Party Advisory
- https://usn.ubuntu.com/4147-1/Third Party Advisory
- https://www.bluetooth.com/security/statement-key-negotiation-of-bluetooth/Third Party Advisory
- https://www.kb.cert.org/vuls/id/918987/Third Party Advisory, US Government Resource
- https://www.usenix.org/conference/usenixsecurity19/presentation/antonioliThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.