CVE-2025-41657CWE-207

AUMA: Incorrect delivery status of the Bluetooth configuration

Medium · published June 10, 2025

CVSS v3.1
4.3
EPSS
0%
Percentile
8.1
In the wild
Unconfirmed
What it is

Due to an undocumented active bluetooth stack on products delivered within the period 01.01.2024 to 09.05.2025 fingerprinting is possible by an unauthenticated adjacent attacker.

The record
Technical detail
CVSS v3.1
4.3 · MEDIUM
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS v4.0
Not supplied
EPSS
0.00185 · 8.1th percentile
Weakness
CWE-207 · Observable Behavioral Discrepancy With Equivalent Products
Published
2025-06-10T10:46Z
EPSS history
Timeline
  • 10 JUN 10:46Z
    AUMA: Incorrect delivery status of the Bluetooth configuration
    cvelistv5