peter bassill · operator
$ cve CVE-2006-6899 JSON

CVE-2006-6899 EXPLOIT

5.4
MEDIUM · CVSS 2.0 · EPSS 3.3% (pctl 88)

Patch early

A public exploit exists.

Description

hidd in BlueZ (bluez-utils) before 2.25 allows remote attackers to obtain control of the (1) Mouse and (2) Keyboard Human Interface Device (HID) via a certain configuration of two HID (PSM) endpoints, operating as a server, aka HidAttack.

Scoring

CVSS5.4 (MEDIUM, v2.0)
VectorAV:A/AC:M/Au:N/C:P/I:P/A:P
EPSS3.32% — more likely to be exploited than 88% of all CVEs
WeaknessCWE-16
On CISA KEVno
Public exploityes
Published2006-12-31
Last modified2026-06-16

Affected (1)

VendorProduct
bluez projectbluez

Public exploits

SourceTitleDate
exploit-dbBlueZ 1.x/2.x - HIDD Bluetooh HID Command Injection2007-11-16

References

→ the Explorer  ·  watch your stack  ·  NVD