SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-3658

This could lead to inadvertent exposure of the bluetooth stack to physically nearby attackers.

MEDIUM 6.5EPSS 0.79%

Does this matter?

Lower severity and a low EPSS score (0.79%). Track it; it rarely justifies an emergency change on its own.

Description

bluetoothd from bluez incorrectly saves adapters' Discoverable status when a device is powered down, and restores it when powered up. If a device is powered down while discoverable, it will be discoverable when powered on again. This could lead to inadvertent exposure of the bluetooth stack to physically nearby attackers.

CVSS 3.1
6.5 MEDIUMCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS
0.79% probability · 54th percentile
CISA KEV
Not listed
Weakness
CWE-863
Affected
bluez/bluez · fedoraproject/fedora
Source
secalert@redhat.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.