PoC Index

CVE-2017-1000250

MEDIUM 6.5EPSS 7.8%

All versions of the SDP server in BlueZ 5.46 and earlier are vulnerable to an information disclosure vulnerability which allows remote attackers to obtain sensitive information from the bluetoothd process memory. This vulnerability lies in the processing of SDP search attribute requests.

CVSS v3.0
6.5 MEDIUMCVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS v2.0
3.3 LOWAV:A/AC:L/Au:N/C:P/I:N/A:N
EPSS
7.77% chance of exploitation in the next 30 days, 94th percentile
Published
2017-09-12
Updated
2024-08-05

Proof-of-concept exploits (1)

References

Related