Nokia Bluetooth Device Unauthorized Access Vulnerability

BID:9032

Info

Nokia Bluetooth Device Unauthorized Access Vulnerability

Bugtraq ID: 9032
Class: Design Error
CVE:
Remote: Yes
Local: No
Published: Nov 12 2003 12:00AM
Updated: Nov 12 2003 12:00AM
Credit: This vulnerability was discovered by Adam Laurie <[email protected]>.
Vulnerable: Nokia Nokia 8910i
Nokia Nokia 8910
Nokia Nokia 7650
Nokia Nokia 6310i
Nokia Nokia 6310
Not Vulnerable:

Discussion

Nokia Bluetooth Device Unauthorized Access Vulnerability

It has been reported that various Bluetooth enabled devices may fail to fully remove previously trusted relationships with other devices. Specifically, the trust of a previously paired device may not be discarded even when the device is no longer in the list of paired devices. As a result, a now potentially untrusted device may be capable of carrying out trusted actions on an unsuspecting users device. This action would go unnoticed, unless the victim user was physically monitoring the display on their device.

Exploit / POC

Nokia Bluetooth Device Unauthorized Access Vulnerability

The researchers who disclosed this information have stated that a number of proof of concept utilities have been developed to carry out this and other Bluetooth-related attacks. However, these tools have not yet been made available.

Solution / Fix

Nokia Bluetooth Device Unauthorized Access Vulnerability

Solution:
The vendor has stated through the media that fixed versions of firmware will not be released.
-----
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.

References

Nokia Bluetooth Device Unauthorized Access Vulnerability

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report