CVE-2020-0556
high
CVSS v3
—
CVSS v2
—
VIR risk
8.0
Description
Improper access control in subsystem for BlueZ before version 5.54 may allow an unauthenticated user to potentially enable escalation of privilege and denial of service via adjacent access
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2020-0556.html
Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2020-0556
Vendor advisory: arch — https://security.archlinux.org/ASA-202003-13
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| debian | bookworm | fixed | 5.50-1.1 |
| debian | bullseye | fixed | 5.50-1.1 |
| debian | forky | fixed | 5.50-1.1 |
| debian | sid | fixed | 5.50-1.1 |
| debian | trixie | fixed | 5.50-1.1 |
| arch | fixed | 5.54-1 | |
| sles | affected | |
References
Verify integrity in audit chain (admin only). AS-IS.