CVE-2017-1000250
All versions of the SDP server in BlueZ 5.46 and earlier are vulnerable to an information disclosure vulnerability which allows remote attackers to obtain sensitive information from the bluetoothd process memory. This vulnerability lies in the processing of SDP search attribute requests.
CVSS
- Versión: 3.0
- Vector: CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Puntuación base: 6.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 7.77%
- Percentil entre todas las CVEs puntuadas: 94
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
💥 Exploits públicos
Hay código de explotación o plantillas de detección públicos. No es lo mismo que explotación activa confirmada (KEV), pero aumenta el riesgo: parchee con prioridad.
- Prueba de concepto en GitHub (no verificada) · Lista de pruebas de concepto en GitHub
⚠️ Las pruebas de concepto de GitHub no están verificadas: algunas son falsas o contienen malware. No las ejecute nunca fuera de un laboratorio aislado.
Tecnologías afectadas (1)
CWE
- CWE-200
Referencias
- http://nvidia.custhelp.com/app/answers/detail/a_id/4561
- http://www.debian.org/security/2017/dsa-3972
- http://www.securityfocus.com/bid/100814
- https://access.redhat.com/errata/RHSA-2017:2685
- https://access.redhat.com/security/vulnerabilities/blueborne
- https://www.armis.com/blueborne
- https://www.kb.cert.org/vuls/id/240311
- https://www.synology.com/support/security/Synology_SA_17_52_BlueBorne
- https://access.redhat.com/security/cve/CVE-2017-1000250
- http://nvidia.custhelp.com/app/answers/detail/a_id/4561
- http://www.debian.org/security/2017/dsa-3972
- http://www.securityfocus.com/bid/100814
- https://access.redhat.com/errata/RHSA-2017:2685
- https://access.redhat.com/security/vulnerabilities/blueborne
- https://www.armis.com/blueborne
- https://www.kb.cert.org/vuls/id/240311
- https://www.synology.com/support/security/Synology_SA_17_52_BlueBorne
JSON original (NVD)
Mostrar
{
"id": "CVE-2017-1000250",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 3.3,
"accessVector": "ADJACENT_NETWORK",
"vectorString": "AV:A/AC:L/Au:N/C:P/I:N/A:N",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "LOW",
"obtainAllPrivilege": false,
"exploitabilityScore": 6.5,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV30": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.0",
"baseScore": 6.5,
"attackVector": "ADJACENT_NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2017-09-12T17:29:00.197",
"references": [
{
"url": "http://nvidia.custhelp.com/app/answers/detail/a_id/4561",
"source": "cve@mitre.org"
},
{
"url": "http://www.debian.org/security/2017/dsa-3972",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/100814",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "cve@mitre.org"
},
{
"url": "https://access.redhat.com/errata/RHSA-2017:2685",
"source": "cve@mitre.org"
},
{
"url": "https://access.redhat.com/security/vulnerabilities/blueborne",
"tags": [
"Not Applicable"
],
"source": "cve@mitre.org"
},
{
"url": "https://www.armis.com/blueborne",
"tags": [
"Exploit",
"Technical Description",
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://www.kb.cert.org/vuls/id/240311",
"tags": [
"Third Party Advisory",
"US Government Resource"
],
"source": "cve@mitre.org"
},
{
"url": "https://www.synology.com/support/security/Synology_SA_17_52_BlueBorne",
"source": "cve@mitre.org"
},
{
"url": "https://access.redhat.com/security/cve/CVE-2017-1000250",
"tags": [
"Issue Tracking",
"Third Party Advisory",
"VDB Entry"
],
"source": "nvd@nist.gov"
},
{
"url": "http://nvidia.custhelp.com/app/answers/detail/a_id/4561",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.debian.org/security/2017/dsa-3972",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/100814",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://access.redhat.com/errata/RHSA-2017:2685",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://access.redhat.com/security/vulnerabilities/blueborne",
"tags": [
"Not Applicable"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.armis.com/blueborne",
"tags": [
"Exploit",
"Technical Description",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.kb.cert.org/vuls/id/240311",
"tags": [
"Third Party Advisory",
"US Government Resource"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.synology.com/support/security/Synology_SA_17_52_BlueBorne",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-200"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "All versions of the SDP server in BlueZ 5.46 and earlier are vulnerable to an information disclosure vulnerability which allows remote attackers to obtain sensitive information from the bluetoothd process memory. This vulnerability lies in the processing of SDP search attribute requests."
},
{
"lang": "es",
"value": "Todas las versiones del servidor SDP en BlueZ 5.46 y anteriores son vulnerables a sufrir una divulgación de información que permite que los atacantes remotos obtengan información sensible de la memoria del proceso bluetoothd. Esta vulnerabilidad se basa en el procesamiento de peticiones del atributo de búsqueda SDP."
}
],
"lastModified": "2026-06-17T00:58:58.960",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:bluez:bluez:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0A6C5D02-8B93-4876-84E2-9C529EF85150",
"versionEndIncluding": "5.46"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}