CVE-2023-51580 is an out-of-bounds read vulnerability in the BlueZ Audio Profile AVRCP, specifically within the avrcp_parse_attribute_list function, affecting BlueZ installations. This flaw allows a network-adjacent attacker to disclose sensitive information via Bluetooth due to improper validation of user-supplied data, leading to a read past the end of an allocated buffer. Rated as Medium severity (CVSS 5.7), exploitation requires user interaction where the target connects to a malicious device. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.66CPE matchmatch criteria | cpe:2.3:a:bluez:bluez:5.66:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.