Summary
A collection of Bluetooth attack vectors were discovered and related vulnerabilities known as "BlueBorne" were disclosed. These vulnerabilities collectively endanger amongst others Windows, Linux and mobile operating systems like Android or IOS. An unauthenticated attacker may take control of devices and perform commands or access sensitive data.
Impact
An unauthenticated, remote attacker may be able to obtain private information about the device or user, execute arbitrary code on the device or perform a virtually invisible Man-in-the-middle (MitM) attack.
Affected Product(s)
Model no. | Product name | Affected versions |
---|---|---|
CT50-Ex vers:all/* | CT50-Ex vers:all/* | |
Cx70-Ex vers:all/* | Cx70-Ex vers:all/* | |
Ex-Handy 09 vers:all/* | Ex-Handy 09 vers:all/* | |
Ex-Handy 209 vers:all/* | Ex-Handy 209 vers:all/* | |
Pad-Ex 01 vers:all/* | Pad-Ex 01 vers:all/* | |
Smart-Ex 01 vers:all/* | Smart-Ex 01 vers:all/* | |
Smart-Ex 201 vers:all/* | Smart-Ex 201 vers:all/* | |
Tab-Ex 01 vers:all/* | Tab-Ex 01 vers:all/* | |
i.roc Ci70-Ex vers:all/* | i.roc Ci70-Ex vers:all/* |
Vulnerabilities
Expand / Collapse allA remote code execution vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-63146237.
A remote code execution vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-63146105.
Microsoft Bluetooth Driver in Windows Server 2008 SP2, Windows 7 SP1, Windows 8.1, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703 allows a spoofing vulnerability due to Microsoft's implementation of the Bluetooth stack, aka "Microsoft Bluetooth Driver Spoofing Vulnerability".
A information disclosure vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-63145701.
A information disclosure vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-63146698.
Remediation
Customers using affected Pepperl+Fuchs / ecom instruments products are recommended to update the device.
For released firmware updates see table below.
Product | Date | Update Source |
---|---|---|
CT50-Ex Android | 09/2017 | FOTA-Update |
CT50-Ex Windows | 10/2017 | Microsoft Update |
Pad-Ex 01 | 09/2017 | Microsoft Update |
Smart-Ex 01 | 09/2018 | FOTA-Update |
Smart-Ex 201 | 10/2018 | FOTA-Update |
In case there is no update available, users should consider the following workaround:
Deactivation of Bluetooth on the device Unused or not needed Bluetooth should be switched off / disabled on affected devices.
Revision History
Version | Date | Summary |
---|---|---|
1 | 14.03.2019 08:52 | Initial revision. |