PT-2006-2374 · Motorola · Motorola Pebl U6+2
Adam Laurie
·
Published
2006-03-23
·
Updated
2018-10-18
·
CVE-2006-1365
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Motorola PEBL U6
Motorola V600
Motorola E398 and other Motorola phones (affected versions not specified)
Description
The issue allows remote attackers to add their Bluetooth device to a target device's list of trusted devices, potentially obtaining AT level access to the target device. This is achieved by initiating and interrupting an OBEX Push Profile that pretends to send a vCard, also known as a "HeloMoto" attack.
Recommendations
For Motorola PEBL U6, consider disabling Bluetooth functionality until a fix is available.
For Motorola V600, restrict access to the device's trusted devices list to minimize the risk of exploitation.
For Motorola E398 and other affected Motorola phones, avoid using the OBEX Push Profile feature until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Motorola E398
Motorola Pebl U6
Motorola V600