Record summary

CVE-2018-5383 has a selected CVSS score of 6.8 (medium). VulnCheck reports CVE-2018-5383 use in known ransomware campaigns.

Description

Bluetooth firmware or operating system software drivers in macOS versions before 10.13, High Sierra and iOS versions before 11.4, and Android versions before the 2018-06-05 patch may not sufficiently validate elliptic curve parameters used to generate public keys during a Diffie-Hellman key exchange, which may allow a remote attacker to obtain the encryption key used by the device.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Feb 25, 2020 · VulnCheck
Reported exploitation
Observed · VulnCheck
Ransomware use
Observed · VulnCheck

Affected products and versions

4
ProductSourceVersion rangeStatus
CVE ListBefore 2018-06-05 patch levelaffected
CVE List11 to < 11.4affected
CVE List10.13 High Sierra to < 10.13.6affected

wl18xx_bluetooth_service_pack

Browse ti / wl18xx_bluetooth_service_pack
VulnCheckVersion data not supplied

References

Showing 12 of 13