Bluetooth firmware or operating system software drivers in macOS versions before 10.13, High Sierra and iOS versions before 11.4, and Android versions before the 2018-06-05 patch may not sufficiently validate elliptic curve parameters used to generate public keys during a Diffie-Hellman key exchange, which may allow a remote attacker to obtain the encryption key used by the device.
2018-08-07T21:29:00.287
2024-11-21T04:08:42.640
Modified
CVSSv3.0: 8.0 (HIGH)
AV:A/AC:M/Au:N/C:P/I:P/A:N
5.5
4.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | android | 6.0 | Yes | |
Operating System | android | 6.0.1 | Yes | |
Operating System | android | 7.0 | Yes | |
Operating System | android | 7.1.1 | Yes | |
Operating System | android | 7.1.2 | Yes | |
Operating System | android | 8.0 | Yes | |
Operating System | android | 8.1 | Yes | |
Operating System | apple | iphone_os | < 11.4 | Yes |
Operating System | apple | mac_os_x | < 10.13 | Yes |