CVE-2023-45866
Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate and establish an encrypted connection, and accept HID keyboard reports, potentially permitting injection of HID messages when no user interaction has occurred in the Central role to authorize such access. An example affected package is bluez 5.64-0ubuntu1 in Ubuntu 22.04LTS. NOTE: in some cases, a CVE-2020-0556 mitigation would have already addressed this Bluetooth HID Hosts issue.
Published:Dec 7, 2023
Last Modified:Nov 4, 2025
EPS:Dec 8, 2023
EPSS Score:0.2657
CVSS Score:6.3
Affected Products
Vendor
Product
Action
Vendor
Apple
Product
Ipados
Apple
Ipados
Vendor
Apple
Product
Iphone Os
Apple
Iphone Os
Vendor
Apple
Product
Iphone Se
Apple
Iphone Se
Vendor
Apple
Product
Macbook Air
Apple
Macbook Air
Vendor
Apple
Product
Macbook Pro
Apple
Macbook Pro
Vendor
Apple
Product
Macos
Apple
Macos
Vendor
Bluproducts
Product
Dash
Bluproducts
Dash
Vendor
Canonical
Product
Ubuntu Linux
Canonical
Ubuntu Linux
Vendor
Debian
Product
Debian Linux
Debian
Debian Linux
Vendor
Fedoraproject
Product
Fedora
Fedoraproject
Fedora
Vendor
Google
Product
Android
Google
Android
Vendor
Google
Product
Nexus 5
Google
Nexus 5
Vendor
Google
Product
Pixel 2
Google
Pixel 2
Vendor
Google
Product
Pixel 4a
Google
Pixel 4a
Vendor
Google
Product
Pixel 6
Google
Pixel 6
Vendor
Google
Product
Pixel 7
Google
Pixel 7
Vendor
Redhat
Product
Enterprise Linux
Redhat
Enterprise Linux
Exploits
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
