CVE-2023-45866

MEDIUMCVSS 6.3/10EPSS 7.88%

Last modified

CVE-2023-45866 is a medium-severity vulnerability rated 6.3/10 on the CVSS scale. Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate and establish an encrypted connection, and accept HID keyboard reports, potentially permitting injection of HID messages when no user interaction has occurred in the Central role to authorize such access. An example affected package is bluez 5.64-0ubuntu1 in Ubuntu 22.04LTS. EPSS estimates a 7.88% chance of exploitation in the next 30 days.

Description

Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate and establish an encrypted connection, and accept HID keyboard reports, potentially permitting injection of HID messages when no user interaction has occurred in the Central role to authorize such access. An example affected package is bluez 5.64-0ubuntu1 in Ubuntu 22.04LTS. NOTE: in some cases, a CVE-2020-0556 mitigation would have already addressed this Bluetooth HID Hosts issue.

Metrics

CVSS 3.1
6.3/10

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

EPSS Probability
7.88%

94.0th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
GoogleAndroid4.2.2
GoogleAndroid6.0.1
GoogleAndroid10.0
GoogleAndroid11.0
GoogleAndroid13.0
GoogleAndroid14.0
CanonicalUbuntu Linux18.04
CanonicalUbuntu Linux20.04
CanonicalUbuntu Linux22.04
CanonicalUbuntu Linux23.10
AppleIphone Os16.6
AppleMacos12.6.7
AppleMacos13.3.3
FedoraprojectFedora38
FedoraprojectFedora39
AppleIpados< 17.2
AppleIphone Os< 17.2
AppleMacos>= 14.0, < 14.2
DebianDebian Linux10.0

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2023-45866?
Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate and establish an encrypted connection, and accept HID keyboard reports, potentially permitting injection of HID messages when no user interaction has occurred in the Central role to authorize such access. An example affected package is bluez 5.64-0ubuntu1 in Ubuntu 22.04LTS. NOTE: in some cases, a CVE-2020-0556 mitigation would have already addressed this Bluetooth HID Hosts issue.
How severe is CVE-2023-45866?
CVE-2023-45866 has a CVSS score of 6.3/10 (MEDIUM severity). The EPSS model estimates a 7.88% probability of exploitation in the next 30 days.
How do I fix CVE-2023-45866?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2023-45866?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST