CVE-2024-45431 describes an improper input validation vulnerability in OpenSynergy BlueSDK (Blue SDK) through version 6.x, specifically within its Bluetooth stack, affecting products like those used in Mercedes, Volkswagen, and Skoda cars. This medium-severity vulnerability (CVSS 5.3) allows an unauthenticated attacker to create an L2CAP channel with a null remote channel ID, potentially leading to information disclosure. While there is no known active exploitation or public exploit code, the vulnerability has garnered significant community discussion and media coverage, indicating awareness and potential future interest.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 6.0.1CPE matchmatch criteria | cpe:2.3:a:opensynergy:blue_sdk:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.