CVE-2018-5383
Last modified
CVE-2018-5383 is a medium-severity vulnerability rated 6.8/10 on the CVSS scale. Bluetooth firmware or operating system software drivers in macOS versions before 10.13, High Sierra and iOS versions before 11.4, and Android versions before the 2018-06-05 patch may not sufficiently validate elliptic curve parameters used to generate public keys during a Diffie-Hellman key exchange, which may allow a remote attacker to obtain the encryption key used by the device.. EPSS estimates a 0.80% chance of exploitation in the next 30 days.
Description
Bluetooth firmware or operating system software drivers in macOS versions before 10.13, High Sierra and iOS versions before 11.4, and Android versions before the 2018-06-05 patch may not sufficiently validate elliptic curve parameters used to generate public keys during a Diffie-Hellman key exchange, which may allow a remote attacker to obtain the encryption key used by the device.
Metrics
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ti | Wl18xx Bluetooth Service Pack | < 4.3 |
| Android | 6.0 | |
| Android | 6.0.1 | |
| Android | 7.0 | |
| Android | 7.1.1 | |
| Android | 7.1.2 | |
| Android | 8.0 | |
| Android | 8.1 | |
| Apple | Iphone Os | < 11.4 |
| Apple | Mac Os X | < 10.13 |
References
- http://www.cs.technion.ac.il/~biham/BT/Mitigation, Third Party Advisory
- http://www.securityfocus.com/bid/104879Broken Link, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1041432Broken Link, Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2019:2169Third Party Advisory
- https://usn.ubuntu.com/4094-1/Third Party Advisory
- https://usn.ubuntu.com/4095-1/Third Party Advisory
- https://usn.ubuntu.com/4095-2/Third Party Advisory
- https://usn.ubuntu.com/4118-1/Third Party Advisory
- https://usn.ubuntu.com/4351-1/Third Party Advisory
- https://www.bluetooth.com/news/unknown/2018/07/bluetooth-sig-security-updateBroken Link, Vendor Advisory
- https://www.kb.cert.org/vuls/id/304725Third Party Advisory
- http://www.cs.technion.ac.il/~biham/BT/Mitigation, Third Party Advisory
- http://www.securityfocus.com/bid/104879Broken Link, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1041432Broken Link, Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2019:2169Third Party Advisory
- https://usn.ubuntu.com/4094-1/Third Party Advisory
- https://usn.ubuntu.com/4095-1/Third Party Advisory
- https://usn.ubuntu.com/4095-2/Third Party Advisory
- https://usn.ubuntu.com/4118-1/Third Party Advisory
- https://usn.ubuntu.com/4351-1/Third Party Advisory
- https://www.bluetooth.com/news/unknown/2018/07/bluetooth-sig-security-updateBroken Link, Vendor Advisory
- https://www.kb.cert.org/vuls/id/304725Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2018-5383?
How severe is CVE-2018-5383?
How do I fix CVE-2018-5383?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-5377Discuz! DiscuzX X3.4 allows remote attackers to bypass inten…
- CVE-2018-5378The Quagga BGP daemon (bgpd) prior to version 1.2.3 does not…7.1
- CVE-2018-5379The Quagga BGP daemon (bgpd) prior to version 1.2.3 can doub…7.5
- CVE-2018-5380The Quagga BGP daemon (bgpd) prior to version 1.2.3 can over…4.3
- CVE-2018-5381The Quagga BGP daemon (bgpd) prior to version 1.2.3 has a bu…6.5
- CVE-2018-5382The default BKS keystore use an HMAC that is only 16 bits lo…4.4
- CVE-2018-5384Navarino Infinity web interface up to version 2.2 exposes an…
- CVE-2018-5385Navarino Infinity is prone to session fixation attacks. The …
- CVE-2018-5386Some Navarino Infinity functions, up to version 2.2, placed …
- CVE-2018-5387Wizkunde SAMLBase may incorrectly utilize the results of XML…7.5
- CVE-2018-5388In stroke_socket.c in strongSwan before 5.6.3, a missing pac…
- CVE-2018-5389The Internet Key Exchange v1 main mode is vulnerable to offl…
Are you affected by CVE-2018-5383?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
