ID

VAR-201301-0160


CVE

CVE-2012-6459


TITLE

Tizen Run on ConnMan Vulnerability in which important information is obtained

Trust: 0.8

sources: JVNDB: JVNDB-2012-005848

DESCRIPTION

ConnMan 1.3 on Tizen continues to list the bluetooth service after offline mode has been enabled, which might allow remote attackers to obtain sensitive information via Bluetooth packets. ConnMan is prone to an information-disclosure vulnerability. Attackers can exploit this issue to obtain sensitive information that may aid in launching further attacks. ConnMan 1.3 is vulnerable; other versions may also be affected

Trust: 1.98

sources: NVD: CVE-2012-6459 // JVNDB: JVNDB-2012-005848 // BID: 57136 // VULMON: CVE-2012-6459

IOT TAXONOMY

category:['network device']sub_category:bluetooth device

Trust: 0.1

sources: OTHER: None

AFFECTED PRODUCTS

vendor:connmanmodel:connmanscope:eqversion:1.3

Trust: 1.7

vendor:intelmodel:connmanscope:eqversion:1.3

Trust: 1.0

vendor:tizenmodel:tizenscope:eqversion:0

Trust: 0.3

sources: BID: 57136 // JVNDB: JVNDB-2012-005848 // CNNVD: CNNVD-201301-011 // NVD: CVE-2012-6459

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2012-6459
value: MEDIUM

Trust: 1.0

NVD: CVE-2012-6459
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201301-011
value: MEDIUM

Trust: 0.6

VULMON: CVE-2012-6459
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2012-6459
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.9

sources: VULMON: CVE-2012-6459 // JVNDB: JVNDB-2012-005848 // CNNVD: CNNVD-201301-011 // NVD: CVE-2012-6459

PROBLEMTYPE DATA

problemtype:CWE-200

Trust: 1.8

sources: JVNDB: JVNDB-2012-005848 // NVD: CVE-2012-6459

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201301-011

TYPE

information disclosure

Trust: 0.6

sources: CNNVD: CNNVD-201301-011

CONFIGURATIONS

sources: JVNDB: JVNDB-2012-005848

PATCH

title:still see bluetooth service even offline mode turned onurl:https://bugs.tizen.org/jira/browse/TIVI-211

Trust: 0.8

title:Debian CVElist Bug Report Logs: connman: CVE-2012-6459url:https://vulmon.com/vendoradvisory?qidtp=debian_cvelist_bugreportlogs&qid=b5850ae259c55ede82dc3b293118af29

Trust: 0.1

sources: VULMON: CVE-2012-6459 // JVNDB: JVNDB-2012-005848

EXTERNAL IDS

db:NVDid:CVE-2012-6459

Trust: 2.9

db:JVNDBid:JVNDB-2012-005848

Trust: 0.8

db:CNNVDid:CNNVD-201301-011

Trust: 0.6

db:BIDid:57136

Trust: 0.3

db:OTHERid:NONE

Trust: 0.1

db:VULMONid:CVE-2012-6459

Trust: 0.1

sources: OTHER: None // VULMON: CVE-2012-6459 // BID: 57136 // JVNDB: JVNDB-2012-005848 // CNNVD: CNNVD-201301-011 // NVD: CVE-2012-6459

REFERENCES

url:https://bugs.tizen.org/jira/browse/tivi-211

Trust: 2.0

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2012-6459

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2012-6459

Trust: 0.8

url:http://connman.net/

Trust: 0.3

url:https://www.tizen.org/about

Trust: 0.3

url:https://ieeexplore.ieee.org/abstract/document/10769424

Trust: 0.1

url:https://cwe.mitre.org/data/definitions/200.html

Trust: 0.1

url:https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=697580

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

sources: OTHER: None // VULMON: CVE-2012-6459 // BID: 57136 // JVNDB: JVNDB-2012-005848 // CNNVD: CNNVD-201301-011 // NVD: CVE-2012-6459

CREDITS

yu liyun

Trust: 0.3

sources: BID: 57136

SOURCES

db:OTHERid: -
db:VULMONid:CVE-2012-6459
db:BIDid:57136
db:JVNDBid:JVNDB-2012-005848
db:CNNVDid:CNNVD-201301-011
db:NVDid:CVE-2012-6459

LAST UPDATE DATE

2025-04-11T20:31:54.832000+00:00


SOURCES UPDATE DATE

db:VULMONid:CVE-2012-6459date:2020-03-05T00:00:00
db:BIDid:57136date:2013-01-02T00:00:00
db:JVNDBid:JVNDB-2012-005848date:2016-02-10T00:00:00
db:CNNVDid:CNNVD-201301-011date:2020-02-10T00:00:00
db:NVDid:CVE-2012-6459date:2025-04-11T00:51:21.963

SOURCES RELEASE DATE

db:VULMONid:CVE-2012-6459date:2013-01-01T00:00:00
db:BIDid:57136date:2013-01-02T00:00:00
db:JVNDBid:JVNDB-2012-005848date:2013-01-04T00:00:00
db:CNNVDid:CNNVD-201301-011date:2013-01-05T00:00:00
db:NVDid:CVE-2012-6459date:2013-01-01T15:55:02.757