PT-2020-8551 · Samsung · Samsung Galaxy Gear
Published
2020-01-22
·
Updated
2020-01-30
·
CVE-2018-16270
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions:
Samsung Galaxy Gear series before build RE2
Description:
The issue allows an unprivileged process to dump Bluetooth HCI packets to an arbitrary file path due to the hcidump utility having no privilege or permission restriction.
Recommendations:
For Samsung Galaxy Gear series before build RE2, update to build RE2 or later to resolve the issue.
Exploit
Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Samsung Galaxy Gear