CVE-2024-8805 is an Improper Access Control vulnerability in BlueZ's HID over GATT Profile, affecting BlueZ installations. This critical flaw allows network-adjacent attackers to execute arbitrary code without authentication due to a lack of authorization checks. With a CVSS score of 8.8 (High), exploitation is straightforward, requiring no user interaction, and can lead to complete compromise of confidentiality, integrity, and availability. Currently, there is no public exploit code, active exploitation, or significant community discussion, and it is not listed in CISA's KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.77CPE matchmatch criteria | cpe:2.3:a:bluez:bluez:5.77:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.