PT-2020-8551 · Samsung · Samsung Galaxy Gear

Published

2020-01-22

·

Updated

2020-01-30

·

CVE-2018-16270

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions: Samsung Galaxy Gear series before build RE2
Description: The issue allows an unprivileged process to dump Bluetooth HCI packets to an arbitrary file path due to the hcidump utility having no privilege or permission restriction.
Recommendations: For Samsung Galaxy Gear series before build RE2, update to build RE2 or later to resolve the issue.

Exploit

Fix

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-16270

Affected Products

Samsung Galaxy Gear