Geeks for your information
Zero-Day RCE Vulnerabilities Expose Millions of BLE-Enabled Devices - Printable Version

+- Geeks for your information (https://www.geeks.fyi)
+-- Forum: News (https://www.geeks.fyi/forumdisplay.php?fid=105)
+--- Forum: Privacy & Security News (https://www.geeks.fyi/forumdisplay.php?fid=107)
+--- Thread: Zero-Day RCE Vulnerabilities Expose Millions of BLE-Enabled Devices (/showthread.php?tid=4367)



Zero-Day RCE Vulnerabilities Expose Millions of BLE-Enabled Devices - silversurfer - 01 November 18

Quote:Bluetooth Low Energy (also known as Bluetooth 4.0, Bluetooth LE, or BLE) is a low-power wireless standard subset of the Bluetooth protocol and specifically designed to be used in Internet of Things (IoT) devices.

Both vulnerabilities expose vulnerable devices to undetected, unauthenticated, and remote wireless attacks, allowing for penetration of networks secure from Internet-based attacks.
This translates into millions of access points and other network devices that use TI BLE chips being exposed to remote attacks.

The Bleedingbit vulnerabilities have been discovered by IoT security research company Armis, the same one who also found the BlueBorne (CVE-2017-1000251) Bluetooth security issues which would allow physically proximate attackers to trigger denial of service states in vulnerable devices.

Source: https://news.softpedia.com/news/zero-day-rce-vulnerabilities-expose-millions-of-ble-enabled-devices-to-attacks-523566.shtml