CVE-2017-0782 is a critical remote code execution vulnerability affecting Android devices running versions 4.4.4 through 8.0, specifically within the Bluetooth component. With a CVSS score of 8.8 (High), this vulnerability allows an unauthenticated attacker to execute arbitrary code on a vulnerable device via an adjacent network attack with low complexity, leading to complete compromise of confidentiality, integrity, and availability. While not currently listed on CISA's KEV catalog, its high EPSS score and significant media coverage, including articles detailing the "BlueBorne" attack, indicate widespread awareness and potential for exploitation. Despite the lack of public exploit code in Metasploit or ExploitDB, the extensive community discussion suggests considerable interest in this flaw.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.0CPE matchmatch criteria | cpe:2.3:o:google:android:4.0:*:*:*:*:*:*:* | ||
4.0.1CPE matchmatch criteria | cpe:2.3:o:google:android:4.0.1:*:*:*:*:*:*:* | ||
4.0.2CPE matchmatch criteria | cpe:2.3:o:google:android:4.0.2:*:*:*:*:*:*:* | ||
4.0.3CPE matchmatch criteria | cpe:2.3:o:google:android:4.0.3:*:*:*:*:*:*:* | ||
4.0.4CPE matchmatch criteria | cpe:2.3:o:google:android:4.0.4:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.