CVE-2018-5383
Last modified
CVE-2018-5383 is a medium-severity vulnerability rated 6.8/10 on the CVSS scale. Bluetooth firmware or operating system software drivers in macOS versions before 10.13, High Sierra and iOS versions before 11.4, and Android versions before the 2018-06-05 patch may not sufficiently validate elliptic curve parameters used to generate public keys during a Diffie-Hellman key exchange, which may allow a remote attacker to obtain the encryption key used by the device.. EPSS estimates a 0.80% chance of exploitation in the next 30 days.
Description
Bluetooth firmware or operating system software drivers in macOS versions before 10.13, High Sierra and iOS versions before 11.4, and Android versions before the 2018-06-05 patch may not sufficiently validate elliptic curve parameters used to generate public keys during a Diffie-Hellman key exchange, which may allow a remote attacker to obtain the encryption key used by the device.
Metrics
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ti | Wl18xx Bluetooth Service Pack | < 4.3 |
| Android | 6.0 | |
| Android | 6.0.1 | |
| Android | 7.0 | |
| Android | 7.1.1 | |
| Android | 7.1.2 | |
| Android | 8.0 | |
| Android | 8.1 | |
| Apple | Iphone Os | < 11.4 |
| Apple | Mac Os X | < 10.13 |
References
- http://www.cs.technion.ac.il/~biham/BT/Mitigation, Third Party Advisory
- http://www.securityfocus.com/bid/104879Broken Link, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1041432Broken Link, Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2019:2169Third Party Advisory
- https://usn.ubuntu.com/4094-1/Third Party Advisory
- https://usn.ubuntu.com/4095-1/Third Party Advisory
- https://usn.ubuntu.com/4095-2/Third Party Advisory
- https://usn.ubuntu.com/4118-1/Third Party Advisory
- https://usn.ubuntu.com/4351-1/Third Party Advisory
- https://www.bluetooth.com/news/unknown/2018/07/bluetooth-sig-security-updateBroken Link, Vendor Advisory
- https://www.kb.cert.org/vuls/id/304725Third Party Advisory
- http://www.cs.technion.ac.il/~biham/BT/Mitigation, Third Party Advisory
- http://www.securityfocus.com/bid/104879Broken Link, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1041432Broken Link, Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2019:2169Third Party Advisory
- https://usn.ubuntu.com/4094-1/Third Party Advisory
- https://usn.ubuntu.com/4095-1/Third Party Advisory
- https://usn.ubuntu.com/4095-2/Third Party Advisory
- https://usn.ubuntu.com/4118-1/Third Party Advisory
- https://usn.ubuntu.com/4351-1/Third Party Advisory
- https://www.bluetooth.com/news/unknown/2018/07/bluetooth-sig-security-updateBroken Link, Vendor Advisory
- https://www.kb.cert.org/vuls/id/304725Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2018-5383?
How severe is CVE-2018-5383?
How do I fix CVE-2018-5383?
Are you affected by CVE-2018-5383?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
