CVE-2024-2104

8.8

Harman · JBL LIVE PRO 2 TWS, JBL TUNE FLEX

Improper BLE security configurations on the device GATT server allow an unauthenticated adjacent attacker to read or write control commands, potentially rendering the device unusable.

Executive summary

A critical vulnerability in JBL audio hardware allows unauthenticated adjacent attackers to gain unauthorized control over device functions via Bluetooth, risking complete loss of device availability.

Vulnerability

This is a missing authentication for critical function vulnerability (CWE-306) affecting the GATT server. An unauthenticated attacker within Bluetooth range can intercept or inject control commands intended for the mobile application service.

Business impact

The ability for an unauthenticated attacker to inject control commands poses a significant operational risk, as it allows for the total loss of device functionality. With a CVSS score of 8.8, this vulnerability is categorized as high severity due to the ease of access for adjacent attackers and the potential for a complete denial of service.

Remediation

Immediate Action: Review the official security advisory provided by the vendor at the certvde.com portal to determine if a firmware update has been released for your specific model.

Proactive Monitoring: Monitor Bluetooth-enabled environments for unusual device behavior or unexpected pairing requests that could indicate exploitation attempts.

Compensating Controls: Disable Bluetooth connectivity when not in use and restrict physical access to the devices to reduce the attack surface for adjacent attackers.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the high CVSS score and the potential for total device compromise, users and administrators should prioritize checking the manufacturer's security portal for firmware updates. If no patch is currently available, maintaining strict physical control over the affected hardware is the most effective method for mitigating the risk of unauthorized adjacent access.

Sources

Originally found and disclosed by Mattar Bernhard from Hummus Sec, per the CVE Program record.