BlueZ HID over GATT Profile Improper Access Control Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of BlueZ. Authentication is not required to exploit this vulnerability. The specific flaw exists within the implementation of the HID over GATT Profile. The issue results from the lack of authorization prior to allowing access to functionality. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-25177.
History

Mon, 03 Nov 2025 23:30:00 +0000

Type Values Removed Values Added
References

Wed, 16 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00349}

epss

{'score': 0.00364}


Fri, 20 Dec 2024 18:30:00 +0000

Type Values Removed Values Added
Weaknesses NVD-CWE-noinfo
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Thu, 05 Dec 2024 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Bluez
Bluez bluez
CPEs cpe:2.3:a:bluez:bluez:5.77:*:*:*:*:*:*:*
Vendors & Products Bluez
Bluez bluez
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 22 Nov 2024 21:15:00 +0000

Type Values Removed Values Added
Description BlueZ HID over GATT Profile Improper Access Control Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of BlueZ. Authentication is not required to exploit this vulnerability. The specific flaw exists within the implementation of the HID over GATT Profile. The issue results from the lack of authorization prior to allowing access to functionality. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-25177.
Title BlueZ HID over GATT Profile Improper Access Control Remote Code Execution Vulnerability
Weaknesses CWE-284
References
Metrics cvssV3_0

{'score': 8.8, 'vector': 'CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: zdi

Published: 2024-11-22T21:02:52.231Z

Updated: 2025-11-03T22:33:02.033Z

Reserved: 2024-09-13T17:57:29.617Z

Link: CVE-2024-8805

cve-icon Vulnrichment

Updated: 2025-11-03T22:33:02.033Z

cve-icon NVD

Status : Modified

Published: 2024-11-22T21:15:18.660

Modified: 2025-11-03T23:17:32.637

Link: CVE-2024-8805

cve-icon Redhat

No data.