CVE-2023-45866

Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate and establish an encrypted connection, and accept HID keyboard reports, potentially permitting injection of HID messages when no user interaction has occurred in the Central role to authorize such access. An example affected package is bluez 5.64-0ubuntu1 in Ubuntu 22.04LTS. NOTE: in some cases, a CVE-2020-0556 mitigation would have already addressed this Bluetooth HID Hosts issue.

Published: 2023-12-08 Last update: 2025-11-04 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2023-45866 is rated Moderate Risk (58.6/100): CVSS Medium severity, with high exploitation likelihood (EPSS 35.98%, 97th percentile). Core evidence: EPSS ranks this CVE among the most likely to be exploited in the near term. Mandatory action: High exploitation likelihood—assess exposure and prioritize remediation.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2023-45866

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-06-05 36.55% 35.98% -0.57%
2 2026-05-23 35.98% 36.55% +0.57%
3 2026-05-13 35.98%

Full EPSS history (69 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2023-45866

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
6.3 3.1 MEDIUM
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L Click to expand
Attack vector (AV:A)
Attacker has to be nearby on the network—same office, same link, that vibe—not the whole wide internet.
Attack complexity (AC:L)
Once they can reach the bug, pulling it off is straightforward—no weird race conditions or rare setup.
Privileges required (PR:N)
No account or special rights needed—anonymous or random user is enough.
User interaction (UI:N)
Nobody has to click “OK” or open a trap file; it can work without a victim helping.
Scope (S:U)
Damage stays in the same “trust bubble” as the broken component—no big spill into unrelated systems.
Confidentiality (C:L)
Some sensitive info could get out, but not a total data dump.
Integrity (I:L)
Attackers could change some data, but it’s limited—not everything goes.
Availability (A:L)
Might cause slowdowns, glitches, or partial disruption—not a full brick.
2.8 3.4 [email protected]

Weakness enumeration for CVE-2023-45866

OS Trackers for CVE-2023-45866

vendor priority summary link
debian not yet assigned CVE-2023-45866 not yet assigned priority: Debian including 1 source packages (bluez), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. https://security-tracker.debian.org/tracker/CVE-2023-45866
gentoo high CVE-2023-45866: 1 GLSA(s) (202401-03), 1 atom(s) (net-wireless/bluez); latest impact high. https://bugs.gentoo.org/buglist.cgi?quicksearch=CVE-2023-45866
redhat medium https://access.redhat.com/security/cve/CVE-2023-45866
suse medium CVE-2023-45866 severity moderate: SUSE including 55 source package names (bluez, bluez-5.13-5.45.1, …), 70 product×package rows across 25 product lines (Image SLES15-SP4-SAP-Azure-LI-BYOS, Image SLES15-SP4-SAP-Azure-LI-BYOS-Production, … (25 product lines)): Fixed 61, Known Not Affected 9. https://www.suse.com/security/cve/CVE-2023-45866/
ubuntu medium CVE-2023-45866 medium priority: Ubuntu including 1 source packages (bluez), 9 status rows across 9 suites (bionic, focal, jammy, lunar, mantic, noble, trusty, upstream, xenial): released 7, ignored 1, needs-triage 1. https://ubuntu.com/security/CVE-2023-45866

Affected software / configurations for CVE-2023-45866

Vendor Product Version Raw CPE
google android 4.2.2 cpe:2.3:o:google:android:4.2.2:*:*:*:*:*:*:*
google android 6.0.1 cpe:2.3:o:google:android:6.0.1:*:*:*:*:*:*:*
google android 10.0 cpe:2.3:o:google:android:10.0:*:*:*:*:*:*:*
google android 11.0 cpe:2.3:o:google:android:11.0:*:*:*:*:*:*:*
google android 13.0 cpe:2.3:o:google:android:13.0:*:*:*:*:*:*:*
google android 14.0 cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:*
canonical ubuntu_linux 18.04 cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
canonical ubuntu_linux 20.04 cpe:2.3:o:canonical:ubuntu_linux:20.04:*:*:*:-:*:*:*
canonical ubuntu_linux 22.04 cpe:2.3:o:canonical:ubuntu_linux:22.04:*:*:*:lts:*:*:*
canonical ubuntu_linux 23.10 cpe:2.3:o:canonical:ubuntu_linux:23.10:*:*:*:*:*:*:*
apple iphone_os 16.6 cpe:2.3:o:apple:iphone_os:16.6:*:*:*:*:*:*:*
apple macos 12.6.7 cpe:2.3:o:apple:macos:12.6.7:*:*:*:*:*:*:*
apple macos 13.3.3 cpe:2.3:o:apple:macos:13.3.3:*:*:*:*:*:*:*
fedoraproject fedora 38 cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*
fedoraproject fedora 39 cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*
apple ipados < 17.2 cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
apple iphone_os < 17.2 cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
apple macos >= 14.0, < 14.2 cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
debian debian_linux 10.0 cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*

References for CVE-2023-45866

URL Tags
http://changelogs.ubuntu.com/changelogs/pool/main/b/bluez/bluez_5.64-0ubuntu1/changelog Release Notes
http://seclists.org/fulldisclosure/2023/Dec/7 Mailing List Third Party Advisory
http://seclists.org/fulldisclosure/2023/Dec/9 Mailing List Third Party Advisory
https://bluetooth.com Not Applicable
https://git.kernel.org/pub/scm/bluetooth/bluez.git/commit/profiles/input?id=25a471a83e02e1effb15d5a488b3f0085eaeb675 Mailing List Patch
https://github.com/skysafe/reblog/tree/main/cve-2023-45866 Third Party Advisory
https://lists.debian.org/debian-lts-announce/2023/12/msg00011.html Mailing List Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/77YQQS5FXPYE6WBBZO3REFIRAUJHERFA/ Mailing List
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/D2N2P5LMP3V7IJONALV2KOFL4NUU23CJ/ Mailing List
https://security.gentoo.org/glsa/202401-03
https://support.apple.com/kb/HT214035 Third Party Advisory
https://support.apple.com/kb/HT214036 Third Party Advisory
https://www.debian.org/security/2023/dsa-5584
https://lists.fedoraproject.org/archives/list/[email protected]/message/77YQQS5FXPYE6WBBZO3REFIRAUJHERFA/
https://lists.fedoraproject.org/archives/list/[email protected]/message/D2N2P5LMP3V7IJONALV2KOFL4NUU23CJ/
cvelogic Threat Intelligence