CVE-2018-5383
Bluetooth firmware or operating system software drivers in macOS versions before 10.13, High Sierra and iOS versions before 11.4, and Android versions before the 2018-06-05 patch may not sufficiently validate elliptic curve parameters used to generate public keys during a Diffie-Hellman key exchange, which may allow a remote attacker to obtain the encryption key used by the device.
Scoring
- Severity
- HIGH
- CVSS base score
- 8
- CVSS vector
- CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N
- EPSS probability
- 0.58%
- CWE
- CWE-325
- Published
- 2018-08-07
- Last modified
- 2026-03-14
Affected products
- Apple macOS
- Apple iOS
- Android Open Source Project Android
Weakness type
Related vulnerabilities
- CVE-2020-15086 — Potential Remote Code Execution in TYPO3 with mediace extension
- CVE-2026-22863 — Deno node:crypto doesn't finalize cipher
- CVE-2020-15098 — Missing Required Cryptographic Step Leading to Sensitive Information Disclosure in TYPO3 CMS
- CVE-2025-30147 — ALTBN128_ADD, ALTBN128_MUL, ALTBN128_PAIRING precompile functions do not check if points are on curve
- CVE-2026-4601 — Versions of the package jsrsasign before 11.1.1 are vulnerable to Missing Cryptographic Step via the KJUR.crypto.DSA.sig
- CVE-2023-46129 — xkeys Seal encryption used fixed key for all encryption
- CVE-2022-20742 — Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software IPsec IKEv2 VPN Information Disclosure Vulnerability
- CVE-2026-76784 — Insufficient Cryptographic Protections in Local Device Communication Protocol on Multiple TP-Link Kasa Smart Home Devices