CVE-2023-24023

Updated: 2024-11-30 03:43:50.889594

Description:

Bluetooth BR/EDR devices with Secure Simple Pairing and Secure Connections pairing in Bluetooth Core Specification 4.2 through 5.4 allow certain man-in-the-middle attacks that force a short key length, and might lead to discovery of the encryption key and live injection, aka BLUFFS.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0
CVSS Version 3.x MEDIUM 6.8

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU kernel 5.14.0 6.8 MEDIUM Ignored 2024-05-10 14:19:08
CentOS 6 ELS kernel 2.6.32 6.8 MEDIUM Ignored 2024-05-10 14:19:08
CentOS 7 ELS kernel 3.10.0 6.8 MEDIUM Ignored 2024-05-10 14:19:08
CentOS 8.4 ELS kernel 4.18.0 6.8 MEDIUM Ignored 2024-06-24 11:22:25
CentOS 8.5 ELS kernel 4.18.0 6.8 MEDIUM Ignored 2024-06-24 11:22:25
CentOS Stream 8 ELS kernel 4.18.0 6.8 MEDIUM Ignored 2024-05-10 14:19:08
CloudLinux 6 ELS kernel 2.6.32 6.8 MEDIUM Ignored 2024-05-10 14:19:08
Oracle Linux 6 ELS kernel 2.6.32 6.8 MEDIUM Ignored 2024-05-10 17:19:32
Ubuntu 16.04 ELS linux-hwe 4.15.0 6.8 MEDIUM Released CLSA-2024:1714065365 2024-04-25 21:41:18
Ubuntu 16.04 ELS linux 4.4.0 6.8 MEDIUM Released CLSA-2024:1714073393 2024-04-25 21:41:23
Total: 11