Multiple Vendor Bluetooth Device Unspecified Information Disclosure Vulnerability
BID:9024
Info
Multiple Vendor Bluetooth Device Unspecified Information Disclosure Vulnerability
| Bugtraq ID: | 9024 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 12 2003 12:00AM |
| Updated: | Nov 12 2003 12:00AM |
| Credit: | This vulnerability was discovered by Adam Laurie <[email protected]>. |
| Vulnerable: |
Nokia Nokia 8910i Nokia Nokia 8910 Nokia Nokia 7650 Nokia Nokia 6310i Nokia Nokia 6310 Ericsson Ericsson T68i Ericsson Ericsson T68 Ericsson Ericsson T610 |
| Not Vulnerable: | |
Discussion
Multiple Vendor Bluetooth Device Unspecified Information Disclosure Vulnerability
It has been reported that various Bluetooth enabled devices may be prone to an information disclosure vulnerability. Details at the current time are vague, however it has been stated that an anonymous user may be capable of connecting to a Bluetooth device and accessing sensitive information stored therein. This could allow an attacker to expose phone book, calendar, and other sensitive information.
Amongst other personal attacks, the exposure of this type of information could aid in identity theft.
It has been reported that various Bluetooth enabled devices may be prone to an information disclosure vulnerability. Details at the current time are vague, however it has been stated that an anonymous user may be capable of connecting to a Bluetooth device and accessing sensitive information stored therein. This could allow an attacker to expose phone book, calendar, and other sensitive information.
Amongst other personal attacks, the exposure of this type of information could aid in identity theft.
Exploit / POC
Multiple Vendor Bluetooth Device Unspecified Information Disclosure Vulnerability
The researchers who disclosed this information have stated that a number of proof of concept utilities have been developed to carry out this and other Bluetooth-related attacks. However, these tools have not yet been made available.
The researchers who disclosed this information have stated that a number of proof of concept utilities have been developed to carry out this and other Bluetooth-related attacks. However, these tools have not yet been made available.
Solution / Fix
Multiple Vendor Bluetooth Device Unspecified Information Disclosure Vulnerability
Solution:
The vendor has stated through the press that fixed versions of firmware will not be made available.
----
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
The vendor has stated through the press that fixed versions of firmware will not be made available.
----
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.