Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2017-17860


In Samsung Gear products, Bluetooth link key is updated to the different key which is same with attacker's link key. It can be attacked without user's intention only if attacker can reveal the Bluetooth address of target device and paired user's smartphone


Published

2018-01-18T22:29:00.233

Last Modified

2024-11-21T03:18:50.310

Status

Modified

Source

[email protected]

Severity

CVSSv3.0: 5.7 (MEDIUM)

CVSSv2 Vector

AV:A/AC:M/Au:N/C:N/I:N/A:C

  • Access Vector: ADJACENT_NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: NONE
  • Availability Impact: COMPLETE
Exploitability Score

5.5

Impact Score

6.9

Weaknesses
  • Type: Primary
    CWE-20

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System google android - Yes
Hardware samsung gear_s2 - No
Hardware samsung gear_s3 - No

References