KDE Connect
cpe:2.3:a:kde:kdeconnect:*:*:*:*:*:*:*
- < 1.33.0
A vulnerability in KDE Connect for Android, prior to version 1.33.0, allows an attacker to unpair two connected devices by sending a crafted invalid discovery packet over broadcast UDP. This exploitation takes advantage of the UDP protocol's lack of authentication, causing the receiving device to mistakenly believe it is being unpaired by a legitimate device.
Exploitation of this vulnerability causes two paired devices to become unpaired, disrupting the connection and requiring users to re-establish the pairing.
Users are advised to update KDE Connect for Android to version 1.33.0 or later. When on untrusted networks, such as those in airports or conferences, it is recommended to stop using KDE Connect.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.