Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Bluetooth implementations may not sufficiently validate elliptic curve parameters during Diffie-Hellman key exchange
Vulnerability Description
Bluetooth firmware or operating system software drivers in macOS versions before 10.13, High Sierra and iOS versions before 11.4, and Android versions before the 2018-06-05 patch may not sufficiently validate elliptic curve parameters used to generate public keys during a Diffie-Hellman key exchange, which may allow a remote attacker to obtain the encryption key used by the device.
CVSS Information
N/A
Vulnerability Type
缺少必要的密码学步骤
Vulnerability Title
Bluetooth 加密问题漏洞
Vulnerability Description
Bluetooth是一种无线技术标准,它能够实现固定设备、移动设备和楼宇个人域网之间的短距离数据交换。 Bluetooth中存在加密问题漏洞,该漏洞源于在Diffie-Hellman密钥交换过程中程序未能充分验证用于生成公钥的椭圆曲线参数。远程攻击者可利用该漏洞获取设备使用的加密密钥,进而拦截,解密,伪造和注入设备消息。以下系统受到影响:macOS 10.13之前版本;macOS High Sierra 11.4之前版本;iOS 11.4之前版本;Android 2018-06-05补丁之前版本。
CVSS Information
N/A
Vulnerability Type
N/A