Bluetooth BR/EDR devices with Secure Simple Pairing and Secure Connections pairing in Bluetooth Core Specification 4.2 through 5.4 allow certain man-in-the-middle attacks that force a short key length, and might lead to discovery of the encryption key and live injection, aka BLUFFS.
[
{
"events": [
{
"introduced": "4.2"
},
{
"last_affected": "5.4"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "10.0.17763.5122"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "10.0.19043.3693"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "10.0.19045.3693"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "10.0.22000.2600"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "10.0.22621.2715"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "10.0.22631.2715"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "10.0.17763.5122"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "10.0.20348.2113"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "10.0.25398.531"
}
]
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-24023.json"