UBUNTU-CVE-2018-10910
Advisory lineage Upstream: 1 Downstream: 1
Upstream
Downstream
Published: 24 Jul 2018, 00:00
Last modified:22 Apr 2026, 11:41
Vulnerability Summary
Overall Risk (default)
low
18/100 CVSS Score
4.5 MEDIUM
3.0 (osv_ubuntu)
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
24 Jul 2018, 00:00
Published
Vulnerability first disclosed
22 Apr 2026, 11:41
Last Modified
Vulnerability information updated
Description
A bug in Bluez may allow for the Bluetooth Discoverable state being set to on when no Bluetooth agent is registered with the system. This situation could lead to the unauthorized pairing of certain Bluetooth devices without any form of authentication. Versions before bluez 5.51 are vulnerable.
CVSS Metrics
- v3.0•MEDIUM•Score: 4.5CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L
Affected Systems
- ubuntu•bluez
all
- ubuntu•gnome-bluetooth
< 3.28.0-2ubuntu0.1