VDB
CVE-2024-0230
CVE-2024-0230
PUBLISHED
CVSS 2.4000000953674316 LOW
A session management issue was addressed with improved checks. This issue is fixed in Magic Keyboard Firmware Update 2.0.6. An attacker with physical access to the accessory may be able to extract its Bluetooth pairing key and monitor Bluetooth traffic.
EPSS 1.22% · 65.9th percentile
Risk Scores
CVSS 3.1
2.4000000953674316
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS Score
1.22%
65.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apple | Magic Keyboard Firmware | 0 |
| apple | magic_keyboard_firmware | 0, 0, 0 |
| Apple | Magic Keyboard Firmware Update | unspecified |
Timeline
- Jan 12, 2024 PoC Published
- Jan 12, 2024 PoC Published
- Jan 12, 2024 CVE Published
- Jan 13, 2024 PoC Published
- Jan 18, 2024 EPSS Score
- Jan 20, 2024 PoC Published
- Jan 22, 2024 PoC Published
- Jan 26, 2024 PoC Published
- Feb 3, 2024 PoC Published
- Feb 7, 2024 PoC Published
- Feb 12, 2024 PoC Published
- Mar 2, 2024 PoC Published