← Back

CVE-2023-45866

nvd nist
Published: Dec 8, 2023Modified: Nov 4, 2025

JSON object

Loading...
6.3
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Exploitability: 2.8 / Impact: 3.4
Source: NVD

Description

Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate and establish an encrypted connection, and accept HID keyboard reports, potentially permitting injection of HID messages when no user interaction has occurred in the Central role to authorize such access. An example affected package is bluez 5.64-0ubuntu1 in Ubuntu 22.04LTS. NOTE: in some cases, a CVE-2020-0556 mitigation would have already addressed this Bluetooth HID Hosts issue.

Affected (19)

Show all products
1 product
Android
1 product
Ubuntu Linux
3 products
Iphone Os
Macos
Ipados
1 product
Fedora
1 product
Debian Linux
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 4.2.2
Running on/withPlatform Versions
Bluproducts
Dash
Version 3.5
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 6.0.1
Running on/withPlatform Versions
Google
Nexus 5
All versions
Configuration C
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Google
Version 10.0
Version 11.0
Running on/withPlatform Versions
Google
Pixel 2
All versions
Configuration D
1 vulnerable · 2 platform
Vulnerable SoftwareAffected Versions
Version 13.0
Running on/withPlatform Versions
Google
Pixel 4a
All versions
Google
Pixel 6
All versions
Configuration E
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 14.0
Running on/withPlatform Versions
Google
Pixel 7
All versions
Configuration F
4 vulnerable
Vulnerable SoftwareAffected Versions
Canonical
Version 18.04
Version 20.04
Version 22.04
Version 23.10
Configuration G
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 16.6
Running on/withPlatform Versions
Apple
Iphone Se
All versions
Configuration H
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 12.6.7
Running on/withPlatform Versions
Apple
Macbook Air
Version 2017
Configuration I
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 13.3.3
Running on/withPlatform Versions
Apple
Macbook Pro
Version m2
Configuration J
2 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 38
Version 39
Configuration K
3 vulnerable
Vulnerable SoftwareAffected Versions
Before 17.2
Before 17.2
From 14.0 to 14.2
Configuration L
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 10.0

References (28)

Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
Not Applicable
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Not Applicable
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.