Description
Bluetooth firmware or operating system software drivers in macOS versions before 10.13, High Sierra and iOS versions before 11.4, and Android versions before the 2018-06-05 patch may not sufficiently validate elliptic curve parameters used to generate public keys during a Diffie-Hellman key exchange, which may allow a remote attacker to obtain the encryption key used by the device.
Published: 2018-08-07
Score: 6.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-1747-1 firmware-nonfree security update
EUVD EUVD EUVD-2018-17154 Bluetooth firmware or operating system software drivers in macOS versions before 10.13, High Sierra and iOS versions before 11.4, and Android versions before the 2018-06-05 patch may not sufficiently validate elliptic curve parameters used to generate public keys during a Diffie-Hellman key exchange, which may allow a remote attacker to obtain the encryption key used by the device.
Ubuntu USN Ubuntu USN USN-4094-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-4095-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-4095-2 Linux kernel (Xenial HWE) vulnerabilities
Ubuntu USN Ubuntu USN USN-4118-1 Linux kernel (AWS) vulnerabilities
Ubuntu USN Ubuntu USN USN-4351-1 Linux firmware vulnerability
History

Thu, 05 Mar 2026 19:00:00 +0000

Type Values Removed Values Added
First Time appeared Ti
Ti wl18xx Bluetooth Service Pack
CPEs cpe:2.3:o:ti:wl18xx_bluetooth_service_pack:*:*:*:*:*:*:*:*
Vendors & Products Ti
Ti wl18xx Bluetooth Service Pack
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Apple Iphone Os Mac Os X
Google Android
Redhat Enterprise Linux
Ti Wl18xx Bluetooth Service Pack
cve-icon MITRE

Status: PUBLISHED

Assigner: certcc

Published:

Updated: 2024-09-16T20:36:44.114Z

Reserved: 2018-01-12T00:00:00.000Z

Link: CVE-2018-5383

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2018-08-07T21:29:00.287

Modified: 2026-03-05T18:54:32.250

Link: CVE-2018-5383

cve-icon Redhat

Severity : Important

Publid Date: 2018-07-23T00:00:00Z

Links: CVE-2018-5383 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses