6.5

CVE-2020-12352

Exploit
Improper access control in BlueZ may allow an unauthenticated user to potentially enable information disclosure via adjacent access.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version >= 5.4 < 5.4.72
   Bluez ≫ Bluez
Linux ≫ Linux Kernel Version >= 5.8.0 < 5.8.16
   Bluez ≫ Bluez
Linux ≫ Linux Kernel Version >= 5.9.0 <= 5.9.13
   Bluez ≫ Bluez
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 5.71% 0.92
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.5 2.8 3.6
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
NIST 3.3 6.5 2.9
AV:A/AC:L/Au:N/C:P/I:N/A:N
CWE-909 Missing Initialization of Resource

The product does not initialize a critical resource.

http://packetstormsecurity.com/files/161229/Kernel-Live-Patch-Security-Notice-LSN-0074-1.html
Third Party Advisory
Exploit
VDB Entry
http://packetstormsecurity.com/files/162131/Linux-Kernel-5.4-BleedingTooth-Remote-Code-Execution.html
Third Party Advisory
VDB Entry
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00435.html?wapkw=CVE-2020-12351
Third Party Advisory