3.3
CVSSv2

CVE-2021-3658

Published: 02/03/2022 Updated: 03/06/2022
CVSS v2 Base Score: 3.3 | Impact Score: 2.9 | Exploitability Score: 6.5
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 294
Vector: AV:A/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

bluetoothd from bluez incorrectly saves adapters' Discoverable status when a device is powered down, and restores it when powered up. If a device is powered down while discoverable, it will be discoverable when powered on again. This could lead to inadvertent exposure of the bluetooth stack to physically nearby attackers.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

bluez bluez

fedoraproject fedora 34

Vendor Advisories

Debian Bug report logs - #991596 bluez: CVE-2021-3658 Package: bluez; Maintainer for bluez is Debian Bluetooth Maintainers <team+pkg-bluetooth@trackerdebianorg>; Source for bluez is src:bluez (PTS, buildd, popcon) Reported by: Moritz Mühlenhoff <jmm@inutilorg> Date: Wed, 28 Jul 2021 09:15:09 UTC Severity: import ...
bluetoothd from bluez incorrectly saves adapters' Discoverable status when a device is powered down, and restores it when powered up If a device is powered down while discoverable, it will be discoverable when powered on again This could lead to inadvertent exposure of the bluetooth stack to physically nearby attackers ...
bluetoothd from bluez incorrectly saves adapters' Discoverable status when a device is powered down, and restores it when powered up If a device is powered down while discoverable, it will be discoverable when powered on again This could lead to inadvertent exposure of the bluetooth stack to physically nearby attackers ...