BLURtooth is a new Bluetooth attack. Devices supporting both Bluetooth BR/EDR and LE using Cross-Transport Key Derivation (CTKD) for pairing are vulnerable to key overwrite, which enables an attacker to to gain additional access to profiles or services that are not restricted by reducing the encryption key strength or overwriting an authenticated key with an unauthenticated key.
Mitsubishi Electric has patched a vulnerability in MC Works64 and MC Works32 initially reported in June.
QNAP is just fixing some vulnerabilities initially publicized in January 2019, part of SOHOpelessy Broken 2.0.
CND News and Blog
New Vulnerabilities Thursday 10 September
New Alerts for IBM, Pepperl+Fuchs, ABB, Dell, and Linux.
Security Wizardry Radar Page provides vulnerability details and visibility for a variety of software and industries.
All devices using the Bluetooth standard 4.0 through 5.0 are vulnerable. Patches not immediately available.
Stay Informed
When you subscribe to the blog, we will send you an e-mail when there are new updates on the site so you wouldn't miss them.
By accepting you will be accessing a service provided by a third-party external to https://www.cndltd.com/