← Vulnerability feed

Vulnerability record · CVE-2024-8805 · published 22 November 2024

CVE-2024-8805: Bluez improper access control vulnerability

Bluez · Bluez

BlueZ HID over GATT Profile Improper Access Control Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of BlueZ. Authentication is not required to exploit this vulnerability. The specific flaw exists within the implementation of the HID over GATT Profile. The issue results from the lack of authorization prior to allowing access to functionality. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-25177.

8.8 CVSS 3.1 High EPSS 2.0% · top 19.7% CWE-284 · Improper access control
8.8CVSS 3.1 base score
2.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

BlueZ HID over GATT Profile Improper Access Control Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of BlueZ. Authentication is not required to exploit this vulnerability. The specific flaw exists within the implementation of the HID over GATT Profile. The issue results from the lack of authorization prior to allowing access to functionality. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-25177.

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-8805 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.1CVE-2021-43400Bluez use after free vulnerabilityAn issue was discovered in gatt-database.c in BlueZ 5.61. A use-after-free can occur when a client disconnects during D-Bus processing of a WriteValu…EPSS 1.7%8.8CVE-2022-39176Bluez vulnerabilityBlueZ before 5.59 allows physically proximate attackers to obtain sensitive information because profiles/audio/avrcp.c does not validate params_len.EPSS 0.71%8.8CVE-2022-39177Bluez vulnerabilityBlueZ before 5.59 allows physically proximate attackers to cause a denial of service because malformed and invalid capabilities can be processed in p…EPSS 0.67%8.8CVE-2022-0204Bluez memory buffer overflow vulnerabilityA heap overflow vulnerability was found in bluez in versions prior to 5.63. An attacker with local network access could pass specially crafted files …EPSS 1.8%8.8CVE-2019-8922Bluez out-of-bounds write vulnerabilityA heap-based buffer overflow was discovered in bluetoothd in BlueZ through 5.48. There isn't any check on whether there is enough space in the destin…EPSS 1.5%8.6CVE-2020-27153Bluez double free vulnerabilityIn BlueZ before 5.55, a double free was found in the gatttool disconnect_cb() routine from shared/att.c. A remote attacker could potentially cause a …EPSS 4.3%8.0CVE-2023-50229Bluez heap-based buffer overflow vulnerabilityBlueZ Phone Book Access Profile Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers …EPSS 2.3%8.0CVE-2023-50230Bluez heap-based buffer overflow vulnerabilityBlueZ Phone Book Access Profile Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers …EPSS 1.5%

Source: NIST National Vulnerability Database (record CVE-2024-8805), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.