CVE-2020-0556: Bluez

High severity, CVSS 7.1. EPSS: 1% chance of exploitation in the next 30 days.

Improper access control in subsystem for BlueZ before version 5.54 may allow an unauthenticated user to potentially enable escalation of privilege and denial of service via adjacent access

Affected products

  • Bluez Bluez: before 5.54 (fixed in 5.54)
  • Canonical Ubuntu Linux: version 16.04 only; version 18.04 only; version 19.10 only
  • Debian Debian Linux: version 8.0 only; version 9.0 only; version 10.0 only
  • Opensuse Leap: version 15.1 only; version 15.2 only

Published 2020-03-12. Last modified 2026-06-17.