Vulnerability Name: | CVE-2006-6899 (CCN-31458) | ||||||||||||||||
Assigned: | 2006-12-28 | ||||||||||||||||
Published: | 2006-12-28 | ||||||||||||||||
Updated: | 2018-10-16 | ||||||||||||||||
Summary: | hidd in BlueZ (bluez-utils) before 2.25 allows remote attackers to obtain control of the (1) Mouse and (2) Keyboard Human Interface Device (HID) via a certain configuration of two HID (PSM) endpoints, operating as a server, aka HidAttack. | ||||||||||||||||
CVSS v3 Severity: | 4.8 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L)
| ||||||||||||||||
CVSS v2 Severity: | 5.4 Medium (CVSS v2 Vector: AV:A/AC:M/Au:N/C:P/I:P/A:P) 4.0 Medium (Temporal CVSS v2 Vector: AV:A/AC:M/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
3.0 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:N/I:P/A:P/E:U/RL:OF/RC:C)
| ||||||||||||||||
Vulnerability Type: | CWE-16 | ||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||
References: | Source: CCN Type: BugTraq Mailing List, Thu Jan 04 2007 - 06:44:26 CST 23C3 - Bluetooth hacking revisted [Summary and Code] Source: MITRE Type: CNA CVE-2006-6899 Source: MISC Type: UNKNOWN http://events.ccc.de/congress/2006-mediawiki//images/f/fb/23c3_Bluetooh_revisited.pdf Source: CCN Type: Collin R. Mulliner's Web site HID Attack (attacking HID host implementations) Source: MISC Type: UNKNOWN http://mulliner.org/bluetooth/hidattack.php Source: OSVDB Type: UNKNOWN 32830 Source: CCN Type: RHSA-2007-0065 Moderate: bluez-utils security update Source: CCN Type: SA23747 BlueZ HID Insecure Device Connection Vulnerability Source: SECUNIA Type: UNKNOWN 23747 Source: SECUNIA Type: UNKNOWN 23798 Source: SECUNIA Type: UNKNOWN 23879 Source: SECUNIA Type: UNKNOWN 25264 Source: CCN Type: ASA-2007-198 bluez-utils security update (RHSA-2007-0065) Source: CCN Type: BlueZ Web site BlueZ - Official Linux Bluetooth protocol stack Source: MANDRIVA Type: UNKNOWN MDKSA-2007:014 Source: CCN Type: OSVDB ID: 32830 BlueZ (bluez-utils) Input Device Hijacking Source: REDHAT Type: UNKNOWN RHSA-2007:0065 Source: BUGTRAQ Type: UNKNOWN 20070104 23C3 - Bluetooth hacking revisted [Summary and Code] Source: BID Type: UNKNOWN 22076 Source: CCN Type: BID-22076 BlueZ HIDD Bluetooh HID Command Injection Vulnerability Source: CCN Type: USN-413-1 BlueZ vulnerability Source: UBUNTU Type: UNKNOWN USN-413-1 Source: VUPEN Type: UNKNOWN ADV-2007-0200 Source: XF Type: UNKNOWN bluez-hid-unauthorized-access(31458) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:10208 | ||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration RedHat 1: Configuration RedHat 2: Configuration RedHat 3: Configuration RedHat 4: Configuration RedHat 5: Denotes that component is vulnerable | ||||||||||||||||
Oval Definitions | |||||||||||||||||
| |||||||||||||||||
BACK |