Attacker Value
Unknown
(0 users assessed)
Exploitability
Unknown
(0 users assessed)
User Interaction
None
Privileges Required
None
Attack Vector
Adjacent_network
0

CVE-2019-9506

Disclosure Date: August 14, 2019
Add MITRE ATT&CK tactics and techniques that apply to this CVE.

Description

The Bluetooth BR/EDR specification up to and including version 5.1 permits sufficiently low encryption key length and does not prevent an attacker from influencing the key length negotiation. This allows practical brute-force attacks (aka “KNOB”) that can decrypt traffic and inject arbitrary ciphertext without the victim noticing.

Add Assessment

No one has assessed this topic. Be the first to add your voice to the community.

CVSS V3 Severity and Metrics
Base Score:
8.1 High
Impact Score:
5.2
Exploitability Score:
2.8
Vector:
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Attack Vector (AV):
Adjacent_network
Attack Complexity (AC):
Low
Privileges Required (PR):
None
User Interaction (UI):
None
Scope (S):
Unchanged
Confidentiality (C):
High
Integrity (I):
High
Availability (A):
None

General Information

Vendors

  • apple,
  • canonical,
  • debian,
  • google,
  • huawei,
  • opensuse,
  • redhat

Products

  • alp-al00b firmware,
  • android -,
  • ares-al00b firmware,
  • ares-al10d firmware,
  • ares-tl00c firmware,
  • asoka-al00ax firmware,
  • atomu-l33 firmware,
  • atomu-l41 firmware,
  • atomu-l42 firmware,
  • barca-al00 firmware,
  • berkeley-al20 firmware,
  • berkeley-l09 firmware,
  • berkeley-tl10 firmware,
  • bla-al00b firmware,
  • bla-l29c firmware,
  • bla-tl00b firmware,
  • cairogo-l22 firmware,
  • charlotte-l29c firmware,
  • columbia-al10b firmware,
  • columbia-al10i firmware,
  • columbia-l29d firmware,
  • columbia-tl00d firmware,
  • cornell-al00a firmware,
  • cornell-al00i firmware,
  • cornell-al00ind firmware,
  • cornell-al10ind firmware,
  • cornell-l29a firmware,
  • cornell-tl10b firmware,
  • debian linux 8.0,
  • dubai-al00a firmware,
  • dura-al00a firmware,
  • dura-tl00a firmware,
  • emily-l29c firmware,
  • emily-l29c firmware 8.1.0.156(c605),
  • enterprise linux 8.0,
  • enterprise linux aus 7.5,
  • enterprise linux eus 7.6,
  • enterprise linux eus 7.7,
  • enterprise linux eus 8.1,
  • enterprise linux eus 8.2,
  • enterprise linux eus 8.4,
  • enterprise linux for real time 7,
  • enterprise linux for real time 8,
  • enterprise linux for real time eus 8.2,
  • enterprise linux for real time eus 8.4,
  • enterprise linux for real time for nfv 7,
  • enterprise linux for real time for nfv 8,
  • enterprise linux for real time for nfv eus 8.2,
  • enterprise linux for real time for nfv eus 8.4,
  • enterprise linux server 7.0,
  • enterprise linux server aus 7.3,
  • enterprise linux server aus 7.4,
  • enterprise linux server aus 7.6,
  • enterprise linux server aus 7.7,
  • enterprise linux server aus 8.2,
  • enterprise linux server aus 8.4,
  • enterprise linux server tus 7.3,
  • enterprise linux server tus 7.4,
  • enterprise linux server tus 7.6,
  • enterprise linux server tus 7.7,
  • enterprise linux server tus 8.2,
  • enterprise linux server tus 8.4,
  • enterprise linux tus 7.6,
  • ever-l29b firmware,
  • figo-l23 firmware,
  • figo-l31 firmware,
  • figo-l31 firmware 8.0.0.122d(c652),
  • figo-tl10b firmware,
  • florida-al20b firmware,
  • florida-l21 firmware,
  • florida-l22 firmware,
  • florida-l23 firmware,
  • florida-tl10b firmware,
  • harry-al00c firmware -,
  • harry-al10b firmware -,
  • harry-tl00c firmware -,
  • hima-l29c firmware -,
  • honor 10 lite firmware -,
  • honor 20 firmware,
  • honor 20 pro firmware,
  • honor 8a firmware -,
  • honor 8x firmware -,
  • honor view 10 firmware -,
  • honor view 20 firmware -,
  • imanager neteco 6000 firmware -,
  • imanager neteco firmware -,
  • iphone os 12.4,
  • jakarta-al00a firmware -,
  • johnson-tl00d firmware -,
  • johnson-tl00f firmware -,
  • katyusha-al00a firmware -,
  • laya-al00ep firmware -,
  • leap 15.0,
  • leap 15.1,
  • leland-l21a firmware -,
  • leland-l31a firmware -,
  • leland-l32a firmware -,
  • leland-l32c firmware -,
  • leland-l42a firmware -,
  • leland-l42c firmware -,
  • leland-tl10b firmware -,
  • leland-tl10c firmware -,
  • lelandp-al00c firmware -,
  • lelandp-al10b firmware -,
  • lelandp-al10d firmware -,
  • lelandp-l22a firmware -,
  • lelandp-l22c firmware -,
  • lelandp-l22d firmware -,
  • london-al40ind firmware -,
  • mac os x 10.12.6,
  • mac os x 10.13.6,
  • mac os x 10.14.5,
  • madrid-al00a firmware -,
  • madrid-tl00a firmware -,
  • mate 20 firmware -,
  • mate 20 pro firmware -,
  • mate 20 x firmware -,
  • mrg realtime 2.0,
  • neo-al00d firmware -,
  • nova 3 firmware -,
  • nova 4 firmware -,
  • nova 5 firmware -,
  • nova 5i pro firmware -,
  • nova lite 3 firmware -,
  • p smart 2019 firmware -,
  • p smart firmware -,
  • p20 firmware -,
  • p20 pro firmware -,
  • p30 firmware -,
  • p30 pro firmware -,
  • paris-al00ic firmware -,
  • paris-l21b firmware -,
  • paris-l21meb firmware -,
  • paris-l29b firmware -,
  • potter-al00c firmware -,
  • potter-al10a firmware -,
  • princeton-al10b firmware -,
  • princeton-al10d firmware -,
  • princeton-tl10c firmware -,
  • sydney-al00 firmware -,
  • sydney-l21 firmware -,
  • sydney-l21br firmware -,
  • sydney-l22 firmware -,
  • sydney-l22br firmware -,
  • sydney-tl00 firmware -,
  • sydneym-al00 firmware -,
  • sydneym-l01 firmware -,
  • sydneym-l03 firmware -,
  • sydneym-l21 firmware -,
  • sydneym-l22 firmware -,
  • sydneym-l23 firmware -,
  • tony-al00b firmware -,
  • tony-tl00b firmware -,
  • tvos 12.4,
  • ubuntu linux 16.04,
  • ubuntu linux 18.04,
  • ubuntu linux 19.04,
  • virtualization host eus 4.2,
  • watchos 5.3,
  • y5 2018 firmware -,
  • y5 lite firmware -,
  • y6 2019 firmware -,
  • y6 prime 2018 firmware -,
  • y6 pro 2019 firmware -,
  • y7 2019 firmware -,
  • y9 2019 firmware -,
  • yale-al00a firmware -,
  • yale-al50a firmware -,
  • yale-l21a firmware -,
  • yale-l61c firmware -,
  • yale-tl00b firmware -,
  • yalep-al10b firmware -

References

Advisory

Additional Info

Technical Analysis