漏洞信息详情
Bluetooth Core Specification 信息泄露漏洞
漏洞简介
Bluetooth Core Specification是一个规范。定义了开发人员用来创建构成蓬勃发展的蓝牙生态系统的可互操作设备的技术构建块。由蓝牙特别兴趣小组(SIG)监督,并由蓝牙SIG工作组 定期更新和增强,以满足不断发展的技术和市场需求。
Bluetooth Core Specification 1.0B版本至5.2版本存在信息泄露漏洞,该漏洞源于Bluetooth legacy BR/EDR PIN码配对时可允许附近未认证的设备在不知道PIN的情况下诱导对端设备的BD ADDR来完成配对。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
https://kb.cert.org/vuls/id/799380
参考网址
来源:MISC
链接:https://kb.cert.org/vuls/id/799380
来源:CONFIRM
链接:https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00520.html
来源:MISC
链接:https://www.bluetooth.com/learn-about-bluetooth/key-attributes/bluetooth-security/reporting-security/
来源:FEDORA
链接:https://lists.fedoraproject.org/archives/list/[email protected]/message/NSS6CTGE4UGTJLCOZOASDR3T3SLL6QJZ/
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.2023
来源:www.cybersecurity-help.cz
链接:https://www.cybersecurity-help.cz/vdb/SB2021070408
来源:device.harmonyos.com
链接:https://device.harmonyos.com/cn/docs/security/update/security-bulletins-phones-202107-0000001170634565
来源:support.lenovo.com
链接:https://support.lenovo.com/us/en/product_security/LEN-51734
来源:vigilance.fr
链接:https://vigilance.fr/vulnerability/Bluetooth-privilege-escalation-via-BR-EDR-Pin-pairing-35546
来源:www.cybersecurity-help.cz
链接:https://www.cybersecurity-help.cz/vdb/SB2021052614
来源:source.android.com
链接:https://source.android.com/security/bulletin/2021-06-01
来源:www.cybersecurity-help.cz
链接:https://www.cybersecurity-help.cz/vdb/SB2021060801
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.1976
来源:www.qualcomm.com
链接:https://www.qualcomm.com/company/product-security/bulletins/june-2021-bulletin
来源:www.cybersecurity-help.cz
链接:https://www.cybersecurity-help.cz/vdb/SB2021061814
受影响实体
暂无
补丁
- Bluetooth Core Specification 信息泄露漏洞的修复措施<!--2021-5-24-->
还没有评论,来说两句吧...