« Volver al listado

CVE-2024-2105

Estado: AplazadaMedia (6.5)—

An unauthorised attacker within bluetooth range may use an improper validation during the BLE connection request to deadlock the affected devices.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-2105",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-2105",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-12-10T15:49:43.543497Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "info@cert.vde.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "ADJACENT_NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "info@cert.vde.com",
      "affectedData": [
        {
          "vendor": "JBL",
          "product": "Flip 5",
          "versions": [
            {
              "status": "affected",
              "version": "*"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "JBL",
          "product": "Flip 6",
          "versions": [
            {
              "status": "affected",
              "version": "*"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "JBL",
          "product": "Pulse 4",
          "versions": [
            {
              "status": "affected",
              "version": "*"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "JBL",
          "product": "Pulse 5",
          "versions": [
            {
              "status": "affected",
              "version": "*"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "JBL",
          "product": "Boombox 2",
          "versions": [
            {
              "status": "affected",
              "version": "*"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "JBL",
          "product": "Boombox 3",
          "versions": [
            {
              "status": "affected",
              "version": "*"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "JBL",
          "product": "Xtreme 3",
          "versions": [
            {
              "status": "affected",
              "version": "*"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2025-12-10T13:16:02.793",
  "references": [
    {
      "url": "https://certvde.com/en/advisories/VDE-2025-089",
      "source": "info@cert.vde.com"
    },
    {
      "url": "https://harman.csaf-tp.certvde.com/.well-known/csaf/white/2025/hbsa-2025-0002.json",
      "source": "info@cert.vde.com"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "info@cert.vde.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-1287"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An unauthorised attacker within bluetooth range may use an improper validation during the BLE connection request to deadlock the affected devices."
    }
  ],
  "lastModified": "2026-06-17T07:23:44.153",
  "sourceIdentifier": "info@cert.vde.com"
}