First published: Tue Dec 20 2005(Updated: )
The default configuration of Widcomm Bluetooth for Windows (BTW) 4.0.1.1500 and earlier, as installed on Belkin Bluetooth Software 1.4.2 Build 10 and ANYCOM Blue USB-130-250 Software 4.0.1.1500, and possibly other devices, sets null Authentication and Authorization values, which allows remote attackers to send arbitrary audio and possibly eavesdrop using the microphone via the Hands Free Audio Gateway and Headset profile.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Belkin Bluetooth Software | =1.4.2_build_10 | |
ANYCOM Blue USB-130-250 Software | =4.0.1.1500 | |
Widcomm Bluetooth Software | =4.0.1.1500 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-4417 is classified as a high severity vulnerability due to its potential for unauthorized remote access.
To fix CVE-2005-4417, update the Widcomm Bluetooth for Windows, ANYCOM Blue USB-130-250 Software, or Belkin Bluetooth Software to a version that has proper authentication and authorization settings.
CVE-2005-4417 affects Broadcom Widcomm Bluetooth 4.0.1.1500, Belkin Bluetooth Software 1.4.2 Build 10, and ANYCOM Blue USB-130-250 Software 4.0.1.1500.
Yes, CVE-2005-4417 can be exploited remotely due to the lack of authentication and authorization settings in the affected software.
Yes, there are known exploits for CVE-2005-4417 that allow attackers to take advantage of the vulnerability through unauthorized remote access.