CVE-2008-4295 EXPLOIT
5.4
MEDIUM · CVSS 2.0 · EPSS 30.1% (pctl 98)
Patch early
A public exploit exists.
Description
Microsoft Windows Mobile 6.0 on HTC Wiza 200 and HTC MDA 8125 devices does not properly handle the first attempt to establish a Bluetooth connection to a peer with a long name, which allows remote attackers to cause a denial of service (device reboot) by configuring a Bluetooth device with a long hci name and (1) connecting directly to the Windows Mobile system or (2) waiting for the Windows Mobile system to scan for nearby devices.
Scoring
| CVSS | 5.4 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:H/Au:N/C:N/I:N/A:C |
| EPSS | 30.14% — more likely to be exploited than 98% of all CVEs |
| Weakness | CWE-20 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2008-09-27 |
| Last modified | 2026-06-16 |
Affected (3)
| Vendor | Product |
|---|---|
| htc | mda |
| htc | wiza |
| microsoft | windows mobile |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Microsoft Windows Mobile 6.0 - Device Long Name Remote Reboot (Denial of Service) | 2008-09-26 |
References
- http://secunia.com/advisories/32066
- http://www.securityfocus.com/bid/31420
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45463
- https://www.exploit-db.com/exploits/6582
- http://secunia.com/advisories/32066
- http://www.securityfocus.com/bid/31420
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45463
- https://www.exploit-db.com/exploits/6582
→ the Explorer · watch your stack · NVD