Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3017▼ 66 respecto a la semana anterior
Críticas / altas1412▲ 56 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)381▼ 129 respecto a la semana anterior
80 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.18% | — | Intel Wireless BluetoothAI | 16/5/2024 | 17/6/2026 | Improper access control for some Intel(R) Wireless Bluetooth products for Windows before version 23.20 may allow an authenticated user to potentially enable denial of service via local access. | |
| Aplazada | Media (4.4) | 0.22% | — | Intel Wireless BluetoothAI | 16/5/2024 | 17/6/2026 | Improper conditions check for some Intel(R) Wireless Bluetooth(R) products for Windows before version 23.20 may allow a privileged user to potentially enable denial of service via local access. | |
| Aplazada | Alta (7.3) | 0.36% | — | Nordic Semiconductor NRF Sniffer FOR Bluetooth LEAI | 14/5/2024 | 17/6/2026 | extcap/nrf_sniffer_ble.py, extcap/nrf_sniffer_ble.sh, extcap/SnifferAPI/*.py in Nordic Semiconductor nRF Sniffer for Bluetooth LE 3.0.0, 3.1.0, 4.0.0, 4.1.0, and 4.1.1 have set incorrect file permission, which allows attackers to do code execution via modified bash and python scripts. | |
| Modificada | Media (6.8) | 1.3% | — | Bluetooth Core SpecificationMicrosoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+6 | 28/11/2023 | 17/6/2026 | Bluetooth BR/EDR devices with Secure Simple Pairing and Secure Connections pairing in Bluetooth Core Specification 4.2 through 5.4 allow certain man-in-the-middle attacks that force a short key length, and might lead to discovery of the encryption key and live injection, aka BLUFFS. | |
| Modificada | Media (6.5) | 0.29% | — | Silabs Bluetooth LOW Energy Software Development KIT | 15/6/2023 | 17/6/2026 | A memory leak in the EFR32 Bluetooth LE stack 5.1.0 through 5.1.1 allows an attacker to send an invalid pairing message and cause future legitimate connection attempts to fail. A reset of the device immediately clears the error. | |
| Modificada | Media (4.3) | 0.41% | — | Bluetooth Core Specification | 2/6/2023 | 17/6/2026 | Bluetooth Classic in Bluetooth Core Specification through 5.3 does not properly conceal device information for Bluetooth transceivers in Non-Discoverable mode. By conducting an efficient over-the-air attack, an attacker can fully extract the permanent, unique Bluetooth MAC identifier, along with device capabilities… | |
| Modificada | Crítica (9.8) | 0.85% | — | Node-bluetooth Project Node-bluetooth | 9/3/2023 | 17/6/2026 | All versions of the package node-bluetooth are vulnerable to Buffer Overflow via the findSerialPortChannel method due to improper user input length validation. | |
| Modificada | Crítica (9.8) | 0.66% | — | Node-bluetooth-serial-port Project Node-bluetooth-serial-port | 9/3/2023 | 17/6/2026 | All versions of the package node-bluetooth-serial-port are vulnerable to Buffer Overflow via the findSerialPortChannel method due to improper user input length validation. | |
| Modificada | Alta (8.8) | 0.78% | — | Infineon Cypress Bluetooth Mesh Software Development KIT | 1/2/2023 | 17/6/2026 | Cypress : https://www.infineon.com/ Cypress Bluetooth Mesh SDK BSA0107_05.01.00-BX8-AMESH-08 is affected by: Buffer Overflow. The impact is: execute arbitrary code (remote). The component is: affected function is lower_transport_layer_on_seg. ¶¶ In Cypress Bluetooth Mesh SDK, there is an out-of-bound write… | |
| Modificada | Alta (8.8) | 0.78% | — | Infineon Cypress Bluetooth Mesh Software Development KIT | 1/2/2023 | 17/6/2026 | Cypress : https://www.infineon.com/ Cypress Bluetooth Mesh SDK BSA0107_05.01.00-BX8-AMESH-08 is affected by: Buffer Overflow. The impact is: execute arbitrary code (remote). The component is: affected function is pb_transport_handle_frag_. ¶¶ In Cypress Bluetooth Mesh SDK, there is an out-of-bound write vulnerability… | |
| Modificada | Alta (8.8) | 0.74% | — | Bestechnic Bluetooth Mesh Software Development KIT | 1/2/2023 | 17/6/2026 | In Bestechnic Bluetooth Mesh SDK (BES2300) V1.0, a buffer overflow vulnerability can be triggered during provisioning, because there is no check for the SegN field of the Transaction Start PDU. | |
| Modificada | Alta (7.5) | 0.37% | — | Bluetooth Core Specification | 12/12/2022 | 17/6/2026 | Bluetooth® Pairing in Bluetooth Core Specification v1.0B through v5.3 may permit an unauthenticated MITM to acquire credentials with two pairing devices via adjacent access when at least one device supports BR/EDR Secure Connections pairing and the other BR/EDR Legacy PIN code pairing if the MITM negotiates BR/EDR… | |
| Modificada | Alta (7.5) | 0.37% | — | Bluetooth Core Specification | 12/12/2022 | 17/6/2026 | Bluetooth® Low Energy Pairing in Bluetooth Core Specification v4.0 through v5.3 may permit an unauthenticated MITM to acquire credentials with two pairing devices via adjacent access when the MITM negotiates Legacy Passkey Pairing with the pairing Initiator and Secure Connections Passkey Pairing with the pairing… | |
| Modificada | Crítica (9.8) | 1.8% | — | Beappsmobile PC Keyboard Wifi&bluetooth | 5/12/2022 | 17/6/2026 | PC Keyboard allows remote unauthenticated users to send instructions to the server to execute arbitrary code without any previous authorization or authentication. CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | |
| Modificada | Media (5.9) | 0.40% | — | Beappsmobile PC Keyboard Wifi & Bluetooth | 2/12/2022 | 17/6/2026 | PC Keyboard WiFi & Bluetooth allows an attacker (in a man-in-the-middle position between the server and a connected device) to see all data (including keypresses) in cleartext. CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N | |
| Modificada | Media (4.3) | 0.35% | — | Bluetooth Core Specification | 8/11/2022 | 17/6/2026 | An information leakage vulnerability in the Bluetooth Low Energy advertisement scan response in Bluetooth Core Specifications 4.0 through 5.2, and extended scan response in Bluetooth Core Specifications 5.0 through 5.2, may be used to identify devices using Resolvable Private Addressing (RPA) by their response or… | |
| Modificada | Media (6.5) | 0.47% | — | Realtek Bluetooth Mesh Software Development KIT | 30/8/2022 | 17/6/2026 | Realtek Linux/Android Bluetooth Mesh SDK has a buffer overflow vulnerability due to insufficient validation for segmented packets’ link parameter. An unauthenticated attacker in the adjacent network can exploit this vulnerability to cause buffer overflow and disrupt service. | |
| Modificada | Media (6.5) | 0.47% | — | Realtek Bluetooth Mesh Software Development KIT | 30/8/2022 | 17/6/2026 | Realtek Linux/Android Bluetooth Mesh SDK has a buffer overflow vulnerability due to insufficient validation for the length of segmented packets’ shift parameter. An unauthenticated attacker in the adjacent network can exploit this vulnerability to cause buffer overflow and disrupt service. | |
| Modificada | Media (6.5) | 0.47% | — | Realtek Bluetooth Mesh Software Development KIT | 30/8/2022 | 17/6/2026 | Realtek Linux/Android Bluetooth Mesh SDK has a buffer overflow vulnerability due to insufficient validation for the size of segmented packets’ reference parameter. An unauthenticated attacker in the adjacent network can exploit this vulnerability to cause buffer overflow and disrupt service. | |
| Modificada | Media (6.5) | 0.37% | — | Realtek Bluetooth Mesh Software Development KIT | 30/8/2022 | 17/6/2026 | Realtek Linux/Android Bluetooth Mesh SDK has a buffer overflow vulnerability due to insufficient validation for broadcast network packet length. An unauthenticated attacker in the adjacent network can exploit this vulnerability to disrupt service. | |
| Modificada | Media (5.3) | 0.40% | — | Bluetooth Core Specification | 25/6/2021 | 17/6/2026 | Unencrypted Bluetooth Low Energy baseband links in Bluetooth Core Specifications 4.0 through 5.2 may permit an adjacent device to inject a crafted packet during the receive window of the listening device before the transmitting device initiates its packet transmission to achieve full MITM status without terminating… | |
| Modificada | Alta (8.1) | 0.85% | — | Bluetooth Mesh Profile | 24/5/2021 | 17/6/2026 | Bluetooth Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device, reflecting the authentication evidence from a Provisioner, to complete authentication without possessing the AuthValue, and potentially acquire a NetKey and AppKey. | |
| Modificada | Alta (8.8) | 0.85% | — | Bluetooth Mesh Profile | 24/5/2021 | 17/6/2026 | Bluetooth Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device (participating in the provisioning protocol) to identify the AuthValue used given the Provisioner’s public key, and the confirmation number and nonce provided by the provisioning device. This could permit a device… | |
| Modificada | Media (4.2) | 0.87% | — | Bluetooth Core SpecificationFedoraproject FedoraDebian LinuxLinux Kernel+15 | 24/5/2021 | 17/6/2026 | Bluetooth LE and BR/EDR secure pairing in Bluetooth Core Specification 2.1 through 5.2 may permit a nearby man-in-the-middle attacker to identify the Passkey used during pairing (in the Passkey authentication procedure) by reflection of the public key and the authentication evidence of the initiating device,… | |
| Modificada | Alta (7.5) | 0.83% | — | Bluetooth Mesh Profile | 24/5/2021 | 17/6/2026 | Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device (without possession of the AuthValue used in the provisioning protocol) to determine the AuthValue via a brute-force attack (unless the AuthValue is sufficiently random and changed each time). |