CVE-2020-16630
TI’s BLE stack caches and reuses the LTK’s property for a bonded mobile.
Does this matter?
Lower severity and a low EPSS score (0.69%). Track it; it rarely justifies an emergency change on its own.
Description
TI’s BLE stack caches and reuses the LTK’s property for a bonded mobile. A LTK can be an unauthenticated-and-no-MITM-protection key created by Just Works or an authenticated-and-MITM-protection key created by Passkey Entry, Numeric Comparison or OOB. Assume that a victim mobile uses secure pairing to pair with a victim BLE device based on TI chips and generate an authenticated-and-MITM-protection LTK. If a fake mobile with the victim mobile’s MAC address uses Just Works and pairs with the victim device, the generated LTK still has the property of authenticated-and-MITM-protection. Therefore, the fake mobile can access attributes with the authenticated read/write permission.
- CVSS 3.1
- 6.8 MEDIUMCVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
- EPSS
- 0.69% probability · 51th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-863
- Affected
- ti/15.4-stack · ti/ble5-stack · ti/dynamic multi-protocal manager · ti/easylink · ti/openthread · ti/z-stack · ti/real-time operating system
- Source
- cve@mitre.org
References
- http://software-dl.ti.com/simplelink/esd/simplelink_cc13x2_26x2_sdk/3.20.00.68/exports/changelog.htmlVendor Advisory
- https://www.usenix.org/system/files/sec20-zhang-yue.pdfExploit, Third Party Advisory
- http://software-dl.ti.com/simplelink/esd/simplelink_cc13x2_26x2_sdk/3.20.00.68/exports/changelog.htmlVendor Advisory
- https://www.usenix.org/system/files/sec20-zhang-yue.pdfExploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.