Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Kasper B. Rasmussen

Pesquisador deUniversity of Oxford
#31442de 53,638
8.1CVSS total
Vulnerabilidades · 1
PT-2019-3023
8.1
2019-04-25
Bluetooth · Bluetooth Br/Edr · CVE-2019-9506
**Name of the Vulnerable Software and Affected Versions** Bluetooth BR/EDR versions up to and including 5.1 **Description** The issue concerns the Bluetooth BR/EDR specification, which permits sufficiently low encryption key length and does not prevent an attacker from influencing the key length negotiation. This allows practical brute-force attacks that can decrypt traffic and inject arbitrary ciphertext without the victim noticing. The vulnerability can be exploited by an unauthenticated, adjacent attacker to initiate a man-in-the-middle attack, reducing the negotiated entropy length used for secure connections. The flaw affects a wide range of Bluetooth-enabled devices, including smartphones, laptops, IoT devices, and industrial devices. **Recommendations** For Bluetooth BR/EDR versions up to and including 5.1, consider disabling the key negotiation process until a patch is available. As a temporary workaround, restrict access to the encryption key negotiation process to minimize the risk of exploitation. Avoid using the Bluetooth BR/EDR protocol for sensitive connections until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.