VDB

CVE-2021-3658

CVE-2021-3658 PUBLISHED CVSS 3.299999952316284 LOW

bluetoothd from bluez incorrectly saves adapters' Discoverable status when a device is powered down, and restores it when powered up. If a device is powered down while discoverable, it will be discoverable when powered on again. This could lead to inadvertent exposure of the bluetooth stack to physically nearby attackers.

EPSS 0.07% · 22.2th percentile

Risk Scores

CVSS v2.0
3.299999952316284
EPSS Score
0.07%
22.2th percentile

Affected Products

VendorProductVersions
n/abluezFixedin - 5.61 and above.
fedoraprojectfedora34
bluezbluez0

Timeline

  • Mar 2, 2022 CVE Published
  • Mar 3, 2022 EPSS Score
  • Apr 24, 2022 EPSS Score
  • Jun 14, 2022 EPSS Score
  • Aug 6, 2022 EPSS Score
  • Sep 26, 2022 EPSS Score
  • Nov 17, 2022 EPSS Score
  • Jan 8, 2023 EPSS Score
  • Feb 28, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Apr 21, 2023 EPSS Score
  • Jun 11, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›