VDB
BDU%3A2019-03002
BDU%3A2019-03002
PUBLISHED
CVSS 7.800000190734863 HIGH
Уязвимость реализации протокола согласования ключей шифрования Bluetooth BR/EDR, связанная с использованием криптографических алгоритмов, содержащих дефекты, позволяющая нарушителю реализовать атаку типа «человек посередине», вмешаться в процедуру настройки шифрования для соединения BR/EDR и уменьшить длину используемого ключа шифрования
Risk Scores
CVSS 2.0
7.800000190734863
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microsoft Corp, Google Inc, Apple Inc., Bluetooth Special Interest Group, Cisco Systems Inc., Сообщество свободного программного обеспечения | Windows 7 Service Pack 1, Windows 8.1, Windows Server 2012, Windows Server 2012 R2, Windows Server 2008 R2 Service Pack 1, Windows RT 8.1, Windows 10, Windows 10 1607, Android, Windows 10 1703, Windows Server 2016, Windows Server 2012 R2 (Server Core installation), Windows Server 2016 (Server Core installation), Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows 10 1709, Windows 10 1803, Windows Server 1803 (Server Core Installation), Windows 10 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows 10 1903, Windows Server 1903 (Server Core Installation), MacOS, tvOS, watchOS, iOS, Bluetooth BR/EDR, IP Phone 8800 Series, Cisco IP Phone 8800 Series with Multiplatform, Cisco Small Business IP Phones, Telepresence Integrator C Series, Linux, Windows Server 2012 (Server Core installation) |
Timeline
- Aug 30, 2019 CVE Published
- May 31, 2024 CVE Updated
- Mar 18, 2026 Distribution Patch
- Mar 18, 2026 Distribution Patch
- Mar 18, 2026 Distribution Patch
- Mar 18, 2026 Security Advisory
- Mar 23, 2026 Distribution Patch
- Mar 23, 2026 Distribution Patch
- Mar 23, 2026 Distribution Patch
References
- https://seclists.org/fulldisclosure/2019/Aug/15 url
- https://support.apple.com/ru-ru/HT210346 url
- https://ubuntu.com/security/notices/USN-4118-1 url
- https://ubuntu.com/security/notices/USN-4147-1 url
- https://usn.ubuntu.com/usn/usn-4147-1 url
- https://vulmon.com/vulnerabilitydetails?qid=CVE-2019-9506 url
- https://www.cve.org/CVERecord?id=CVE-2019-9506 url
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-9506 advisory
- https://source.android.com/security/bulletin/2019-08-01 advisory
- https://kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.133 advisory
- https://kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.1.17 advisory
- https://bugzilla.kernel.org/show_bug.cgi?id=203997 url
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9506 url
- https://kb.cert.org/vuls/id/918987/ url
- https://kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.4.185 url
- https://knobattack.com/ url
- https://nvd.nist.gov/vuln/detail/CVE-2019-9506 url
- https://seclists.org/fulldisclosure/2019/Aug/11 url
- https://seclists.org/fulldisclosure/2019/Aug/13 url
- https://seclists.org/fulldisclosure/2019/Aug/14 url
…and 8 more