CVE-2022-24695

Source
https://cve.org/CVERecord?id=CVE-2022-24695
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-24695.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-24695
Downstream
Published
2023-06-02T12:15:09.243Z
Modified
2026-03-14T11:37:27.931885Z
Severity
  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
[none]
Details

Bluetooth Classic in Bluetooth Core Specification through 5.3 does not properly conceal device information for Bluetooth transceivers in Non-Discoverable mode. By conducting an efficient over-the-air attack, an attacker can fully extract the permanent, unique Bluetooth MAC identifier, along with device capabilities and identifiers, some of which may contain identifying information about the device owner. This additionally allows the attacker to establish a connection to the target device.

References

Affected packages

Git /

Affected ranges

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-24695.json"
unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "5.3"
            }
        ]
    }
]