CVE-2023-45866 describes a Bluetooth vulnerability in BlueZ HID Hosts, affecting products from Apple, Google, Canonical, Debian, and Fedora. It allows an unauthenticated peripheral HID device to establish an encrypted connection and inject HID messages without user authorization, potentially leading to keystroke injection. With a CVSS score of 6.3 (Medium), this vulnerability is network-adjacent, low complexity, and can impact confidentiality, integrity, and availability. While not on the KEV catalog, it has a high EPSS score and FAUCET Risk Score, indicating significant exploitability potential. Community discussion and media coverage are extensive, with reports of a 0-click Proof-of-Concept for Android 10 and below, suggesting active exploitation or high interest.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.2.2CPE matchmatch criteria | cpe:2.3:o:google:android:4.2.2:*:*:*:*:*:*:* | ||
6.0.1CPE matchmatch criteria | cpe:2.3:o:google:android:6.0.1:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:google:android:10.0:*:*:*:*:*:*:* | ||
11.0CPE matchmatch criteria | cpe:2.3:o:google:android:11.0:*:*:*:*:*:*:* | ||
13.0CPE matchmatch criteria | cpe:2.3:o:google:android:13.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2023-45866
Nov 12, 2024HP ThinPro 8.1 SP 2 Security Updates
Apr 12, 2024HP ThinPro 8.1 SP 2 Security Updates
Apr 12, 2024Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate and establish an encrypted connection and accept HID keyboard reports potentially permitting injection of HID messages when no user interaction has occurred in the Central role to authorize such access. An example affected package is bluez 5.64-0ubuntu1 in Ubuntu 22.04LTS. NOTE: in some cases a CVE-2020-0556 mitigation would have already addressed this Bluetooth HID Hosts issue.
Dec 12, 2023bluez: unauthorized HID device connections allows keystroke injection and arbitrary commands execution
Dec 7, 2023