CVE-2019-9506
Vulnerability Summary
Timeline
Description
The Bluetooth BR/EDR specification up to and including version 5.1 permits sufficiently low encryption key length and does not prevent an attacker from influencing the key length negotiation. This allows practical brute-force attacks (aka "KNOB") that can decrypt traffic and inject arbitrary ciphertext without the victim noticing.
CVSS Metrics
- v4.0•LOW•Score: 2.3CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
- v3.1•HIGH•Score: 8.1CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
- v3.0•HIGH•Score: 7.6CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
- v2.0•MEDIUM•Score: 4.8AV:A/AC:L/Au:N/C:P/I:P/A:N
EPSS Trends
Current EPSS score: 2.69%• Percentile: 85%
Techniques & Countermeasures
- CWE-310•Cryptographic Issues
Weaknesses in this category are related to the design and implementation of data confidentiality and integrity. Frequently these deal with the use of encoding techniques, encryption libraries, and hashing algorithms. The weaknesses in this category could lead to a degradation of the quality data if they are not addressed.
- CWE-327•Use of a Broken or Risky Cryptographic Algorithm
The product uses a broken or risky cryptographic algorithm or protocol.
Affected Systems
- apple•iphone_os
12.4
- apple•mac_os_x
10.12.6 | 10.13.6 | 10.14.5
- apple•tvos
12.4
- apple•watchos
5.3
- bluetooth•br/edr
5.1
- canonical•ubuntu_linux
16.04 | 18.04 | 19.04
- debian•linux
< 5.2.6-1 | < 5.2.6-1 | < 5.2.6-1 | < 5.2.6-1
- ubuntu•linux
all | < 4.4.0-159.187 | < 4.15.0-60.67
- ubuntu•linux-aws
< 4.4.0-1054.58 | < 4.4.0-1090.101 | < 4.15.0-1047.49
- ubuntu•linux-aws-fips
< 4.15.0-2018.18 | all
- ubuntu•linux-aws-hwe
< 4.15.0-1047.49~16.04.1
- ubuntu•linux-azure
< 4.15.0-1059.64~14.04.1
- ubuntu•linux-azure-fde
all
- ubuntu•linux-azure-fde-5.15
< 5.15.0-1114.123~20.04.1
- ubuntu•linux-azure-fips
< 4.15.0-2006.7 | all
- ubuntu•linux-bluefield
all
- ubuntu•linux-fips
< 4.4.0-1017.22
- ubuntu•linux-gcp
< 4.15.0-1041.43 | < 4.15.0-1042.45
- ubuntu•linux-gcp-fips
all
- ubuntu•linux-gke
all
- ubuntu•linux-gke-4.15
< 4.15.0-1041.43
- ubuntu•linux-gke-5.0
< 5.0.0-1020.20~18.04.1
- ubuntu•linux-hwe
< 4.15.0-60.67~16.04.1 | < 5.0.0-31.33~18.04.1
- ubuntu•linux-hwe-edge
all
- ubuntu•linux-intel-iot-realtime
all
- ubuntu•linux-lts-xenial
< 4.4.0-164.192~14.04.1
- ubuntu•linux-oem
< 4.15.0-1056.65
- ubuntu•linux-oem-osp1
< 5.0.0-1024.27
- ubuntu•linux-oracle
< 4.15.0-1022.25~16.04.1 | < 4.15.0-1022.25
- ubuntu•linux-raspi-realtime
all
- ubuntu•linux-raspi2
< 4.4.0-1118.127 | < 4.15.0-1044.47
- ubuntu•linux-realtime
all
- ubuntu•linux-riscv
all | all
- ubuntu•linux-snapdragon
< 4.4.0-1122.128 | < 4.15.0-1062.69
- debian•debian_linux
8.0
- google•android
na
- huawei•alp-al00b_firmware
< 9.1.0.333\(c00e333r2p1t8\)
- huawei•ares-al00b_firmware
< 9.1.0.160\(c00e160r2p5t8\)
- huawei•ares-al10d_firmware
< 9.1.0.160\(c00e160r2p5t8\)
- huawei•ares-tl00c_firmware
< 9.1.0.165\(c01e165r2p5t8\)
- huawei•asoka-al00ax_firmware
< 9.1.1.181\(c00e48r6p1\)
- huawei•atomu-l33_firmware
< 8.0.0.147\(c605custc605d1\)
- huawei•atomu-l41_firmware
< 8.0.0.153\(c461custc461d1\)
- huawei•atomu-l42_firmware
< 8.0.0.155\(c636custc636d1\)
- huawei•barca-al00_firmware
< 8.0.0.366\(c00\)
- huawei•berkeley-al20_firmware
< 9.1.0.333\(c00e333r2p1t8\)
- huawei•berkeley-l09_firmware
< 9.1.0.332\(c432e5r1p13t8\) | < 9.1.0.350\(c10e3r1p14t8\) | < 9.1.0.350\(c636e4r1p13t8\)
- huawei•berkeley-tl10_firmware
< 9.1.0.333\(c01e333r1p1t8\)
- huawei•bla-al00b_firmware
< 9.1.0.329\(c786e320r2p1t8\)
- huawei•bla-l29c_firmware
< 9.1.0.300\(c605e2r1p12t8\) | < 9.1.0.306\(c185e2r1p13t8\) | < 9.1.0.306\(c432e4r1p11t8\) | < 9.1.0.306\(c636e2r1p13t8\) | < 9.1.0.307\(c635e4r1p13t8\)
Showing first 50 affected entries in server-rendered view.
References (37)
- https://www.kb.cert.org/vuls/id/918987/
- http://www.cs.ox.ac.uk/publications/publication12404-abstract.html
- https://www.usenix.org/conference/usenixsecurity19/presentation/antonioli
- https://www.bluetooth.com/security/statement-key-negotiation-of-bluetooth/
- http://seclists.org/fulldisclosure/2019/Aug/14
- http://seclists.org/fulldisclosure/2019/Aug/11
- http://seclists.org/fulldisclosure/2019/Aug/13
- http://seclists.org/fulldisclosure/2019/Aug/15
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20190828-01-knob-en
- https://usn.ubuntu.com/4115-1/
- https://usn.ubuntu.com/4118-1/
- https://lists.debian.org/debian-lts-announce/2019/09/msg00014.html
- https://lists.debian.org/debian-lts-announce/2019/09/msg00015.html
- https://lists.debian.org/debian-lts-announce/2019/09/msg00025.html
- https://usn.ubuntu.com/4147-1/
- https://access.redhat.com/errata/RHSA-2019:2975
- http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00037.html
- http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00036.html
- https://access.redhat.com/errata/RHSA-2019:3076
- https://access.redhat.com/errata/RHSA-2019:3055
- https://access.redhat.com/errata/RHSA-2019:3089
- https://access.redhat.com/errata/RHSA-2019:3187
- https://access.redhat.com/errata/RHSA-2019:3165
- https://access.redhat.com/errata/RHSA-2019:3217
- https://access.redhat.com/errata/RHSA-2019:3220
- https://access.redhat.com/errata/RHSA-2019:3231
- https://access.redhat.com/errata/RHSA-2019:3218
- https://access.redhat.com/errata/RHSA-2019:3309
- https://access.redhat.com/errata/RHSA-2019:3517
- https://access.redhat.com/errata/RHSA-2020:0204
- https://ubuntu.com/security/CVE-2019-9506
- https://knobattack.com/
- https://ubuntu.com/security/notices/USN-4115-1
- https://ubuntu.com/security/notices/USN-4118-1
- https://ubuntu.com/security/notices/USN-4147-1
- https://www.cve.org/CVERecord?id=CVE-2019-9506
- https://security-tracker.debian.org/tracker/CVE-2019-9506