Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2019-9506


The Bluetooth BR/EDR specification up to and including version 5.1 permits sufficiently low encryption key length and does not prevent an attacker from influencing the key length negotiation. This allows practical brute-force attacks (aka "KNOB") that can decrypt traffic and inject arbitrary ciphertext without the victim noticing.


Security Impact Summary

This vulnerability carries a HIGH severity rating with a CVSS v3.1 score of 8.1, indicating it requires adjacent network access with relatively low complexity without requiring user interaction and does not require pre-existing privileges . The vulnerability impacts confidentiality (data exposure), integrity (unauthorized modifications), for affected systems. Impacting 274 products from google, from blackberry, from apple and 271 others, organizations running these solutions should prioritize assessment and patching.

Historical Context

First disclosed in 2019, this vulnerability was reported during a period defined by widespread IoT adoption challenges, mobile security concerns, and the emergence of advanced persistent threat (APT) techniques. Contemporary mitigation strategies focused on secure development practices and third-party component vetting.


Published

2019-08-14T17:15:11.597

Last Modified

2024-11-21T04:51:45.113

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.1 (HIGH)

CVSSv2 Vector

AV:A/AC:L/Au:N/C:P/I:P/A:N

  • Access Vector: ADJACENT_NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

6.5

Impact Score

4.9

Weaknesses
  • Type: Secondary
    CWE-310
  • Type: Primary
    CWE-327

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System google android - Yes
Hardware blackberry blackberry - No
Operating System apple iphone_os 12.4 Yes
Operating System apple mac_os_x 10.12.6 Yes
Operating System apple mac_os_x 10.13.6 Yes
Operating System apple mac_os_x 10.14.5 Yes
Operating System apple tvos 12.4 Yes
Operating System apple watchos 5.3 Yes
Operating System canonical ubuntu_linux 16.04 Yes
Operating System canonical ubuntu_linux 18.04 Yes
Operating System canonical ubuntu_linux 19.04 Yes
Operating System debian debian_linux 8.0 Yes
Operating System opensuse leap 15.0 Yes
Operating System opensuse leap 15.1 Yes
Application redhat mrg_realtime 2.0 Yes
Application redhat virtualization_host_eus 4.2 Yes
Operating System redhat enterprise_linux 8.0 Yes
Operating System redhat enterprise_linux_aus 7.5 Yes
Operating System redhat enterprise_linux_eus 7.6 Yes
Operating System redhat enterprise_linux_eus 7.7 Yes
Operating System redhat enterprise_linux_eus 8.1 Yes
Operating System redhat enterprise_linux_eus 8.2 Yes
Operating System redhat enterprise_linux_eus 8.4 Yes
Operating System redhat enterprise_linux_for_real_time 7 Yes
Operating System redhat enterprise_linux_for_real_time 8 Yes
Operating System redhat enterprise_linux_for_real_time_eus 8.2 Yes
Operating System redhat enterprise_linux_for_real_time_eus 8.4 Yes
Operating System redhat enterprise_linux_for_real_time_for_nfv 7 Yes
Operating System redhat enterprise_linux_for_real_time_for_nfv 8 Yes
Operating System redhat enterprise_linux_for_real_time_for_nfv_eus 8.2 Yes
Operating System redhat enterprise_linux_for_real_time_for_nfv_eus 8.4 Yes
Operating System redhat enterprise_linux_server 7.0 Yes
Operating System redhat enterprise_linux_server_aus 7.3 Yes
Operating System redhat enterprise_linux_server_aus 7.4 Yes
Operating System redhat enterprise_linux_server_aus 7.6 Yes
Operating System redhat enterprise_linux_server_aus 7.7 Yes
Operating System redhat enterprise_linux_server_aus 8.2 Yes
Operating System redhat enterprise_linux_server_aus 8.4 Yes
Operating System redhat enterprise_linux_server_tus 7.3 Yes
Operating System redhat enterprise_linux_server_tus 7.4 Yes
Operating System redhat enterprise_linux_server_tus 7.6 Yes
Operating System redhat enterprise_linux_server_tus 7.7 Yes
Operating System redhat enterprise_linux_server_tus 8.2 Yes
Operating System redhat enterprise_linux_server_tus 8.4 Yes
Operating System redhat enterprise_linux_tus 7.6 Yes
Operating System huawei alp-al00b_firmware < 9.1.0.333\(c00e333r2p1t8\) Yes
Hardware huawei alp-al00b - No
Operating System huawei ares-al00b_firmware < 9.1.0.160\(c00e160r2p5t8\) Yes
Hardware huawei ares-al00b - No
Operating System huawei ares-al10d_firmware < 9.1.0.160\(c00e160r2p5t8\) Yes
Hardware huawei ares-al10d - No
Operating System huawei ares-tl00c_firmware < 9.1.0.165\(c01e165r2p5t8\) Yes
Hardware huawei ares-tl00c - No
Operating System huawei asoka-al00ax_firmware < 9.1.1.181\(c00e48r6p1\) Yes
Hardware huawei asoka-al00ax - No
Operating System huawei atomu-l33_firmware < 8.0.0.147\(c605custc605d1\) Yes
Hardware huawei atomu-l33 - No
Operating System huawei atomu-l41_firmware < 8.0.0.153\(c461custc461d1\) Yes
Hardware huawei atomu-l41 - No
Operating System huawei atomu-l42_firmware < 8.0.0.155\(c636custc636d1\) Yes
Hardware huawei atomu-l42 - No
Operating System huawei bla-al00b_firmware < 9.1.0.329\(c786e320r2p1t8\) Yes
Hardware huawei bla-al00b - No
Operating System huawei bla-l29c_firmware < 9.1.0.300\(c605e2r1p12t8\) Yes
Hardware huawei bla-l29c - No
Operating System huawei bla-tl00b_firmware < 9.1.0.329\(c01e320r1p1t8\) Yes
Hardware huawei bla-tl00b - No
Operating System huawei barca-al00_firmware < 8.0.0.366\(c00\) Yes
Hardware huawei barca-al00 - No
Operating System huawei berkeley-al20_firmware < 9.1.0.333\(c00e333r2p1t8\) Yes
Hardware huawei berkeley-al20 - No
Operating System huawei berkeley-l09_firmware < 9.1.0.332\(c432e5r1p13t8\) Yes
Hardware huawei berkeley-l09 - No
Operating System huawei berkeley-tl10_firmware < 9.1.0.333\(c01e333r1p1t8\) Yes
Hardware huawei berkeley-tl10 - No
Operating System huawei cairogo-l22_firmware < cairogo-l22c461b153 Yes
Hardware huawei cairogo-l22 - No
Operating System huawei charlotte-l29c_firmware < 9.1.0.311\(c605e2r1p11t8\) Yes
Hardware huawei charlotte-l29c - No
Operating System huawei columbia-al10b_firmware < 9.1.0.333\(c00e333r1p1t8\) Yes
Hardware huawei columbia-al10b - No
Operating System huawei columbia-al10i_firmware < 9.1.0.335\(c675e8r1p9t8\) Yes
Hardware huawei columbia-al10i - No
Operating System huawei columbia-l29d_firmware < 9.1.0.350\(c10e5r1p14t8\) Yes
Hardware huawei columbia-l29d - No
Operating System huawei columbia-tl00d_firmware < 8.1.0.186\(c01gt\) Yes
Hardware huawei columbia-tl00d - No
Operating System huawei cornell-al00a_firmware < 9.1.0.333\(c00e333r1p1t8\) Yes
Hardware huawei cornell-al00a - No
Operating System huawei cornell-al00i_firmware < 9.1.0.363\(c675e3r1p9t8\) Yes
Hardware huawei cornell-al00i - No
Operating System huawei cornell-al00ind_firmware < 8.2.0.141\(c675custc675d1gt\) Yes
Hardware huawei cornell-al00ind - No
Operating System huawei cornell-al10ind_firmware < 9.1.0.363\(c675e2r1p9t8\) Yes
Hardware huawei cornell-al10ind - No
Operating System huawei cornell-l29a_firmware < 9.1.0.336\(c636e2r1p12t8\) Yes
Hardware huawei cornell-l29a - No
Operating System huawei cornell-tl10b_firmware < 9.1.0.333\(c01e333r1p1t8\) Yes
Hardware huawei cornell-tl10b - No
Operating System huawei dubai-al00a_firmware < 8.2.0.190\(c00r2p2\) Yes
Hardware huawei dubai-al00a - No
Operating System huawei dura-al00a_firmware < 1.0.0.182\(c00\) Yes
Hardware huawei dura-al00a - No
Operating System huawei dura-tl00a_firmware < 1.0.0.176\(c01\) Yes
Hardware huawei dura-tl00a - No
Operating System huawei emily-l29c_firmware 8.1.0.156\(c605\) Yes
Hardware huawei emily-l29c - No
Operating System huawei ever-l29b_firmware < 9.1.0.338\(c185e3r3p1\) Yes
Hardware huawei ever-l29b - No
Operating System huawei figo-l23_firmware < 9.1.0.160\(c605e6r1p5t8\) Yes
Hardware huawei figo-l23 - No
Operating System huawei figo-l31_firmware 8.0.0.122d\(c652\) Yes
Hardware huawei figo-l31 - No
Operating System huawei figo-tl10b_firmware < 9.1.0.130\(c01e115r2p8t8\) Yes
Hardware huawei figo-tl10b - No
Operating System huawei florida-al20b_firmware < 9.1.0.128\(c00e112r1p6t8\) Yes
Hardware huawei florida-al20b - No
Operating System huawei florida-l21_firmware < 9.1.0.150\(c185e6r1p5t8\) Yes
Hardware huawei florida-l21 - No
Operating System huawei florida-l22_firmware < 9.1.0.150\(c636e6r1p5t8\) Yes
Hardware huawei florida-l22 - No
Operating System huawei florida-l23_firmware < 9.1.0.154\(c605e7r1p2t8\) Yes
Hardware huawei florida-l23 - No
Operating System huawei florida-tl10b_firmware < 9.1.0.128\(c01e112r1p6t8\) Yes
Hardware huawei florida-tl10b - No
Operating System huawei honor_20_firmware < 9.1.0.143\(c675e8r2p1\) Yes
Hardware huawei honor_20 - No
Operating System huawei honor_20_pro_firmware < 9.1.0.154\(c185e2r5p1\) Yes
Hardware huawei honor_20_pro - No
Operating System huawei mate_20_firmware - Yes
Hardware huawei mate_20 - No
Operating System huawei mate_20_pro_firmware - Yes
Hardware huawei mate_20_pro - No
Operating System huawei mate_20_x_firmware - Yes
Hardware huawei mate_20_x - No
Operating System huawei p_smart_firmware - Yes
Hardware huawei p_smart - No
Operating System huawei p_smart_2019_firmware - Yes
Hardware huawei p_smart_2019 - No
Operating System huawei p20_firmware - Yes
Hardware huawei p20 - No
Operating System huawei p20_pro_firmware - Yes
Hardware huawei p20_pro - No
Operating System huawei p30_firmware - Yes
Hardware huawei p30 - No
Operating System huawei p30_pro_firmware - Yes
Hardware huawei p30_pro - No
Operating System huawei y5_2018_firmware - Yes
Hardware huawei y5_2018 - No
Operating System huawei y5_lite_firmware - Yes
Hardware huawei y5_lite - No
Operating System huawei y6_2019_firmware - Yes
Hardware huawei y6_2019 - No
Operating System huawei y6_prime_2018_firmware - Yes
Hardware huawei y6_prime_2018 - No
Operating System huawei y6_pro_2019_firmware - Yes
Hardware huawei y6_pro_2019 - No
Operating System huawei y7_2019_firmware - Yes
Hardware huawei y7_2019 - No
Operating System huawei y9_2019_firmware - Yes
Hardware huawei y9_2019 - No
Operating System huawei nova_3_firmware - Yes
Hardware huawei nova_3 - No
Operating System huawei nova_4_firmware - Yes
Hardware huawei nova_4 - No
Operating System huawei nova_5_firmware - Yes
Hardware huawei nova_5 - No
Operating System huawei nova_5i_pro_firmware - Yes
Hardware huawei nova_5i_pro - No
Operating System huawei nova_lite_3_firmware - Yes
Hardware huawei nova_lite_3 - No
Operating System huawei harry-al00c_firmware - Yes
Hardware huawei harry-al00c - No
Operating System huawei harry-al10b_firmware - Yes
Hardware huawei harry-al10b - No
Operating System huawei harry-tl00c_firmware - Yes
Hardware huawei harry-tl00c - No
Operating System huawei hima-l29c_firmware - Yes
Hardware huawei hima-l29c - No
Operating System huawei honor_10_lite_firmware - Yes
Hardware huawei honor_10_lite - No
Operating System huawei honor_8a_firmware - Yes
Hardware huawei honor_8a - No
Operating System huawei honor_8x_firmware - Yes
Hardware huawei honor_8x - No
Operating System huawei honor_view_10_firmware - Yes
Hardware huawei honor_view_10 - No
Operating System huawei honor_view_20_firmware - Yes
Hardware huawei honor_view_20 - No
Operating System huawei jakarta-al00a_firmware - Yes
Hardware huawei jakarta-al00a - No
Operating System huawei johnson-tl00d_firmware - Yes
Hardware huawei johnson-tl00d - No
Operating System huawei johnson-tl00f_firmware - Yes
Hardware huawei johnson-tl00f - No
Operating System huawei katyusha-al00a_firmware - Yes
Hardware huawei katyusha-al00a - No
Operating System huawei laya-al00ep_firmware - Yes
Hardware huawei laya-al00ep - No
Operating System huawei leland-l21a_firmware - Yes
Hardware huawei leland-l21a - No
Operating System huawei leland-l31a_firmware - Yes
Hardware huawei leland-l31a - No
Operating System huawei leland-l32a_firmware - Yes
Hardware huawei leland-l32a - No
Operating System huawei leland-l32c_firmware - Yes
Hardware huawei leland-l32c - No
Operating System huawei leland-l42a_firmware - Yes
Hardware huawei leland-l42a - No
Operating System huawei leland-l42c_firmware - Yes
Hardware huawei leland-l42c - No
Operating System huawei leland-tl10b_firmware - Yes
Hardware huawei leland-tl10b - No
Operating System huawei leland-tl10c_firmware - Yes
Hardware huawei leland-tl10c - No
Operating System huawei lelandp-al00c_firmware - Yes
Hardware huawei lelandp-al00c - No
Operating System huawei lelandp-al10b_firmware - Yes
Hardware huawei lelandp-al10b - No
Operating System huawei lelandp-al10d_firmware - Yes
Hardware huawei lelandp-al10d - No
Operating System huawei lelandp-l22a_firmware - Yes
Hardware huawei lelandp-l22a - No
Operating System huawei lelandp-l22c_firmware - Yes
Hardware huawei lelandp-l22c - No
Operating System huawei lelandp-l22d_firmware - Yes
Hardware huawei lelandp-l22d - No
Operating System huawei london-al40ind_firmware - Yes
Hardware huawei london-al40ind - No
Operating System huawei madrid-al00a_firmware - Yes
Hardware huawei madrid-al00a - No
Operating System huawei madrid-tl00a_firmware - Yes
Hardware huawei madrid-tl00a - No
Operating System huawei neo-al00d_firmware - Yes
Hardware huawei neo-al00d - No
Operating System huawei paris-al00ic_firmware - Yes
Hardware huawei paris-al00ic - No
Operating System huawei paris-l21b_firmware - Yes
Hardware huawei paris-l21b - No
Operating System huawei paris-l21meb_firmware - Yes
Hardware huawei paris-l21meb - No
Operating System huawei paris-l29b_firmware - Yes
Hardware huawei paris-l29b - No
Operating System huawei potter-al00c_firmware - Yes
Hardware huawei potter-al00c - No
Operating System huawei potter-al10a_firmware - Yes
Hardware huawei potter-al10a - No
Operating System huawei princeton-al10b_firmware - Yes
Hardware huawei princeton-al10b - No
Operating System huawei princeton-al10d_firmware - Yes
Hardware huawei princeton-al10d - No
Operating System huawei princeton-tl10c_firmware - Yes
Hardware huawei princeton-tl10c - No
Operating System huawei sydney-al00_firmware - Yes
Hardware huawei sydney-al00 - No
Operating System huawei sydney-l21_firmware - Yes
Hardware huawei sydney-l21 - No
Operating System huawei sydney-l21br_firmware - Yes
Hardware huawei sydney-l21br - No
Operating System huawei sydney-l22_firmware - Yes
Hardware huawei sydney-l22 - No
Operating System huawei sydney-l22br_firmware - Yes
Hardware huawei sydney-l22br - No
Operating System huawei sydney-tl00_firmware - Yes
Hardware huawei sydney-tl00 - No
Operating System huawei sydneym-al00_firmware - Yes
Hardware huawei sydneym-al00 - No
Operating System huawei sydneym-l01_firmware - Yes
Hardware huawei sydneym-l01 - No
Operating System huawei sydneym-l03_firmware - Yes
Hardware huawei sydneym-l03 - No
Operating System huawei sydneym-l21_firmware - Yes
Hardware huawei sydneym-l21 - No
Operating System huawei sydneym-l22_firmware - Yes
Hardware huawei sydneym-l22 - No
Operating System huawei sydneym-l23_firmware - Yes
Hardware huawei sydneym-l23 - No
Operating System huawei tony-al00b_firmware - Yes
Hardware huawei tony-al00b - No
Operating System huawei tony-tl00b_firmware - Yes
Hardware huawei tony-tl00b - No
Operating System huawei yale-al00a_firmware - Yes
Hardware huawei yale-al00a - No
Operating System huawei yale-al50a_firmware - Yes
Hardware huawei yale-al50a - No
Operating System huawei yale-l21a_firmware - Yes
Hardware huawei yale-l21a - No
Operating System huawei yale-l61c_firmware - Yes
Hardware huawei yale-l61c - No
Operating System huawei yale-tl00b_firmware - Yes
Hardware huawei yale-tl00b - No
Operating System huawei yalep-al10b_firmware - Yes
Hardware huawei yalep-al10b - No
Operating System huawei imanager_neteco_firmware - Yes
Hardware huawei imanager_neteco - No
Operating System huawei imanager_neteco_6000_firmware - Yes
Hardware huawei imanager_neteco_6000 - No
Operating System huawei bla-l29c_firmware < 9.1.0.306\(c185e2r1p13t8\) Yes
Hardware huawei bla-l29c - No
Operating System huawei bla-l29c_firmware < 9.1.0.306\(c432e4r1p11t8\) Yes
Hardware huawei bla-l29c - No
Operating System huawei bla-l29c_firmware < 9.1.0.306\(c636e2r1p13t8\) Yes
Hardware huawei bla-l29c - No
Operating System huawei bla-l29c_firmware < 9.1.0.307\(c635e4r1p13t8\) Yes
Hardware huawei bla-l29c - No
Operating System huawei berkeley-l09_firmware < 9.1.0.350\(c10e3r1p14t8\) Yes
Hardware huawei berkeley-l09 - No
Operating System huawei berkeley-l09_firmware < 9.1.0.350\(c636e4r1p13t8\) Yes
Hardware huawei berkeley-l09 - No
Operating System huawei charlotte-l29c_firmware < 9.1.0.325\(c185e4r1p11t8\) Yes
Hardware huawei charlotte-l29c - No
Operating System huawei charlotte-l29c_firmware < 9.1.0.325\(c636e2r1p12t8\) Yes
Hardware huawei charlotte-l29c - No
Operating System huawei charlotte-l29c_firmware < 9.1.0.328\(c432e5r1p9t8\) Yes
Hardware huawei charlotte-l29c - No
Operating System huawei charlotte-l29c_firmware < 9.1.0.328\(c782e10r1p9t8\) Yes
Hardware huawei charlotte-l29c - No
Operating System huawei columbia-l29d_firmware < 9.1.0.350\(c185e3r1p12t8\) Yes
Hardware huawei columbia-l29d - No
Operating System huawei columbia-l29d_firmware < 9.1.0.350\(c461e3r1p11t8\) Yes
Hardware huawei columbia-l29d - No
Operating System huawei columbia-l29d_firmware < 9.1.0.350\(c636e3r1p13t8\) Yes
Hardware huawei columbia-l29d - No
Operating System huawei columbia-l29d_firmware < 9.1.0.351\(c432e5r1p13t8\) Yes
Hardware huawei columbia-l29d - No
Operating System huawei cornell-l29a_firmware < 9.1.0.341\(c185e1r1p9t8\) Yes
Hardware huawei cornell-l29a - No
Operating System huawei cornell-l29a_firmware < 9.1.0.342\(c461e1r1p9t8\) Yes
Hardware huawei cornell-l29a - No
Operating System huawei cornell-l29a_firmware < 9.1.0.347\(c432e1r1p9t8\) Yes
Hardware huawei cornell-l29a - No
Operating System huawei emily-l29c_firmware < 9.1.0.311\(c461e2r1p11t8\) Yes
Hardware huawei emily-l29c - No
Operating System huawei emily-l29c_firmware < 9.1.0.325\(c185e2r1p12t8\) Yes
Hardware huawei emily-l29c - No
Operating System huawei emily-l29c_firmware < 9.1.0.325\(c636e7r1p13t8\) Yes
Hardware huawei emily-l29c - No
Operating System huawei emily-l29c_firmware < 9.1.0.326\(c635e2r1p11t8\) Yes
Hardware huawei emily-l29c - No
Operating System huawei emily-l29c_firmware < 9.1.0.328\(c432e7r1p11t8\) Yes
Hardware huawei emily-l29c - No
Operating System huawei figo-l31_firmware < 9.1.0.122\(c09e7r1p5t8\) Yes
Hardware huawei figo-l31 - No
Operating System huawei figo-l31_firmware < 9.1.0.137\(c33e8r1p5t8\) Yes
Hardware huawei figo-l31 - No
Operating System huawei figo-l31_firmware < 9.1.0.137\(c530e8r1p5t8\) Yes
Hardware huawei figo-l31 - No
Operating System huawei figo-l31_firmware < 9.1.0.158\(c432e8r1p5t8\) Yes
Hardware huawei figo-l31 - No
Operating System huawei figo-l31_firmware < 9.1.0.165\(c10e8r1p5t8\) Yes
Hardware huawei figo-l31 - No
Operating System huawei florida-l21_firmware < 9.1.0.150\(c432e6r1p5t8\) Yes
Hardware huawei florida-l21 - No
Operating System huawei honor_20_firmware < 9.1.0.149\(c675e8r2p1\) Yes
Hardware huawei honor_20 - No
Operating System huawei honor_20_pro_firmware < 9.1.0.154\(c185e2r5p1\) Yes
Hardware huawei honor_20_pro - No
Operating System huawei honor_20_pro_firmware < 9.1.0.154\(c432e2r5p1\) Yes
Hardware huawei honor_20_pro - No
Operating System huawei honor_20_pro_firmware < 9.1.0.154\(c636e2r3p1\) Yes
Hardware huawei honor_20_pro - No
Operating System huawei honor_20_pro_firmware < 9.1.0.155\(c10e2r3p1\) Yes
Hardware huawei honor_20_pro - No
Operating System huawei honor_20_pro_firmware < 9.1.0.170\(c185e2r5p1\) Yes
Hardware huawei honor_20_pro - No
Operating System huawei honor_20_pro_firmware < 9.1.0.170\(c636e2r3p1\) Yes
Hardware huawei honor_20_pro - No
Operating System huawei honor_20_pro_firmware < 9.1.0.171\(c10e2r3p1\) Yes
Hardware huawei honor_20_pro - No
Operating System huawei honor_20_pro_firmware < 9.1.0.172\(c432e2r5p1\) Yes
Hardware huawei honor_20_pro - No

References

How SecUtils Interprets This CVE

SecUtils normalizes and enriches National Vulnerability Database (NVD) records by standardizing vendor and product identifiers, aggregating vulnerability metadata from both NVD and MITRE sources, and providing structured context for security teams. For google's affected products, we extract Common Platform Enumeration (CPE) data, Common Weakness Enumeration (CWE) classifications, CVSS severity metrics, and reference data to enable rapid vulnerability prioritization and asset correlation. This record contains no exploit code, proof-of-concept instructions, or attack methodologies—only defensive intelligence necessary for patch management, risk assessment, and security operations.