7.5
CVE-2018-16270
- EPSS 0.36%
- Veröffentlicht 22.01.2020 14:15:11
- Zuletzt bearbeitet 21.11.2024 03:52:25
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Samsung Galaxy Gear series before build RE2 includes the hcidump utility with no privilege or permission restriction. This allows an unprivileged process to dump Bluetooth HCI packets to an arbitrary file path.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Samsung ≫ Galaxy Gear Firmware Version < re2
Samsung ≫ Gear 2 Firmware Version < re2
Samsung ≫ Gear Live Firmware Version < re2
Samsung ≫ Gear S Firmware Version < re2
Samsung ≫ Gear S2 Firmware Version < re2
Samsung ≫ Gear S3 Firmware Version < re2
Samsung ≫ Gear Sport Firmware Version < re2
Samsung ≫ Gear Fit Firmware Version < re2
Samsung ≫ Gear Fit 2 Firmware Version < re2
Samsung ≫ Gear Fit 2 Pro Firmware Version < re2
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.36% | 0.575 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:N/I:P/A:N
|
CWE-269 Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.