CVE-2020-10135
Legacy pairing and secure-connections pairing authentication in Bluetooth BR/EDR Core Specification v5.2 and earlier may allow an unauthenticated user to complete authentication without pairing credentials via adjacent access.
Does this matter?
Lower severity and a low EPSS score (2.37%). Track it; it rarely justifies an emergency change on its own.
Description
Legacy pairing and secure-connections pairing authentication in Bluetooth BR/EDR Core Specification v5.2 and earlier may allow an unauthenticated user to complete authentication without pairing credentials via adjacent access. An unauthenticated, adjacent attacker could impersonate a Bluetooth BR/EDR master or slave to pair with a previously paired remote device to successfully complete the authentication procedure without knowing the link key.
- CVSS 3.1
- 5.4 MEDIUMCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
- EPSS
- 2.37% probability · 83th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-757, CWE-290
- Affected
- bluetooth/bluetooth core · opensuse/leap
- Source
- cret@cert.org
References
- http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00009.htmlBroken Link, Mailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00047.htmlBroken Link, Mailing List, Third Party Advisory
- http://packetstormsecurity.com/files/157922/Bluetooth-Impersonation-Attack-BIAS-Proof-Of-Concept.htmlThird Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2020/Jun/5Exploit, Mailing List, Third Party Advisory
- https://francozappa.github.io/about-bias/Third Party Advisory
- https://kb.cert.org/vuls/id/647177/Third Party Advisory, US Government Resource
- https://www.bluetooth.com/learn-about-bluetooth/bluetooth-technology/bluetooth-security/bias-vulnerability/Vendor Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00009.htmlBroken Link, Mailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00047.htmlBroken Link, Mailing List, Third Party Advisory
- http://packetstormsecurity.com/files/157922/Bluetooth-Impersonation-Attack-BIAS-Proof-Of-Concept.htmlThird Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2020/Jun/5Exploit, Mailing List, Third Party Advisory
- https://francozappa.github.io/about-bias/Third Party Advisory
- https://kb.cert.org/vuls/id/647177/Third Party Advisory, US Government Resource
- https://www.bluetooth.com/learn-about-bluetooth/bluetooth-technology/bluetooth-security/bias-vulnerability/Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.