CVE-2017-0781 is a critical remote code execution (RCE) vulnerability within the Android Bluetooth system, affecting Android versions 4.4.4 through 8.0. This vulnerability, part of the "BlueBorne" attack vector, allows an unauthenticated attacker to execute arbitrary code on a vulnerable device without user interaction, simply by being within Bluetooth range. With a CVSS score of 8.8 (High) and a FAUCET Risk Score of 98/100, the potential impact includes complete compromise of confidentiality, integrity, and availability. While not listed in CISA's KEV catalog, exploit code is publicly available on ExploitDB, and there is significant community discussion and media coverage, indicating widespread awareness and potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.0CPE matchmatch criteria | cpe:2.3:o:google:android:4.0:*:*:*:*:*:*:* | ||
4.0.1CPE matchmatch criteria | cpe:2.3:o:google:android:4.0.1:*:*:*:*:*:*:* | ||
4.0.2CPE matchmatch criteria | cpe:2.3:o:google:android:4.0.2:*:*:*:*:*:*:* | ||
4.0.3CPE matchmatch criteria | cpe:2.3:o:google:android:4.0.3:*:*:*:*:*:*:* | ||
4.0.4CPE matchmatch criteria | cpe:2.3:o:google:android:4.0.4:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.