← Vulnerability feed

Vulnerability record · CVE-2017-1000250 · published 12 September 2017

CVE-2017-1000250: Bluez information exposure vulnerability

Bluez · Bluez

All versions of the SDP server in BlueZ 5.46 and earlier are vulnerable to an information disclosure vulnerability which allows remote attackers to obtain sensitive information from the bluetoothd process memory. This vulnerability lies in the processing of SDP search attribute requests.

6.5 CVSS 3.0 Medium EPSS 7.8% · top 5.6% CWE-200 · Information exposure
6.5CVSS 3.0 base score, v2 3.3
7.8%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
17References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

All versions of the SDP server in BlueZ 5.46 and earlier are vulnerable to an information disclosure vulnerability which allows remote attackers to obtain sensitive information from the bluetoothd process memory. This vulnerability lies in the processing of SDP search attribute requests.

CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-1000250 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.1CVE-2021-43400Bluez use after free vulnerabilityAn issue was discovered in gatt-database.c in BlueZ 5.61. A use-after-free can occur when a client disconnects during D-Bus processing of a WriteValu…EPSS 1.7%8.8CVE-2024-8805Bluez improper access control vulnerabilityBlueZ HID over GATT Profile Improper Access Control Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to exec…EPSS 2.0%8.8CVE-2022-39176Bluez vulnerabilityBlueZ before 5.59 allows physically proximate attackers to obtain sensitive information because profiles/audio/avrcp.c does not validate params_len.EPSS 0.71%8.8CVE-2022-39177Bluez vulnerabilityBlueZ before 5.59 allows physically proximate attackers to cause a denial of service because malformed and invalid capabilities can be processed in p…EPSS 0.67%8.8CVE-2022-0204Bluez memory buffer overflow vulnerabilityA heap overflow vulnerability was found in bluez in versions prior to 5.63. An attacker with local network access could pass specially crafted files …EPSS 1.8%8.8CVE-2019-8922Bluez out-of-bounds write vulnerabilityA heap-based buffer overflow was discovered in bluetoothd in BlueZ through 5.48. There isn't any check on whether there is enough space in the destin…EPSS 1.5%8.6CVE-2020-27153Bluez double free vulnerabilityIn BlueZ before 5.55, a double free was found in the gatttool disconnect_cb() routine from shared/att.c. A remote attacker could potentially cause a …EPSS 4.3%8.0CVE-2023-50229Bluez heap-based buffer overflow vulnerabilityBlueZ Phone Book Access Profile Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers …EPSS 2.3%

Source: NIST National Vulnerability Database (record CVE-2017-1000250), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.