Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2017-1000250

26
FAUCET Score

CVE-2017-1000250 is an information disclosure vulnerability in the SDP server of BlueZ 5.46 and earlier, affecting Bluetooth-enabled devices including Amazon Echo and Google Home. This medium-severity vulnerability (CVSS 6.5) allows remote attackers on an adjacent network to obtain sensitive information from the bluetoothd process memory without user interaction. While there are no public exploits available in Metasploit, Nuclei, or ExploitDB, the vulnerability has garnered significant community discussion and media coverage, indicating high awareness and potential for future exploitation.

Impacted Technologies

VendorProductVersion(s)CPE
<= 5.46CPE matchmatch criteria
cpe:2.3:a:bluez:bluez:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.0

6.5MEDIUM

CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
2.8
Impact Score
3.6
CvssVersion
3.0

Exploit Intelligence

EPSS Score
7.77%
Probability of exploitation in next 30 days
EPSS Percentile
94.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.0777 is in the 99th percentile among its peer group of 1,802 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (3)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: bluez-0:4.66-2.el6_9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: bluez-0:5.44-4.el7_4
View patch
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: bluez-utils

Vendor Advisories (1)

redhatCVE-2017-1000250Moderate

bluez: Out-of-bounds heap read in service_search_attr_req function

Sep 12, 2017

References

nvidia.custhelp.com / app/answers/detail/a_id/4561
access.redhat.com / errata/RHSA-2017:2685
access.redhat.com / security/vulnerabilities/blueborne
Not Applicable
armis.com / blueborne
ExploitTechnical DescriptionThird Party Advisory
kb.cert.org / vuls/id/240311
Third Party AdvisoryUS Government Resource
synology.com / support/security/Synology_SA_17_52_BlueBorne
debian.org / security/2017/dsa-3972
securityfocus.com / bid/100814
Third Party AdvisoryVDB Entry
access.redhat.com / security/cve/CVE-2017-1000250
Issue TrackingThird Party AdvisoryVDB Entry