Description
Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate and establish an encrypted connection, and accept HID keyboard reports, potentially permitting injection of HID messages when no user interaction has occurred in the Central role to authorize such access. An example affected package is bluez 5.64-0ubuntu1 in Ubuntu 22.04LTS. NOTE: in some cases, a CVE-2020-0556 mitigation would have already addressed this Bluetooth HID Hosts issue.
Exploits (10)
nomisec
WORKING POC
1,776 stars
by pentestfunctions · poc
https://github.com/pentestfunctions/BlueDucky
nomisec
NO CODE
1 stars
by AvishekDhakal · poc
https://github.com/AvishekDhakal/CVE-2023-45866_EXPLOITS
References (15)
Scores
CVSS v3
6.3
EPSS
0.3492
EPSS Percentile
97.0%
Attack Vector
ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Details
CWE
CWE-287
Status
published
Products (19)
apple/ipados
< 17.2
apple/iphone_os
16.6
apple/iphone_os
< 17.2
apple/macos
12.6.7
apple/macos
13.3.3
apple/macos
14.0 - 14.2
canonical/ubuntu_linux
18.04
canonical/ubuntu_linux
20.04
canonical/ubuntu_linux
22.04
canonical/ubuntu_linux
23.10
... and 9 more
Published
Dec 08, 2023
Tracked Since
Feb 18, 2026