VulnerabilityModified
CVE-2020-26555
Bluetooth legacy BR/EDR PIN code pairing in Bluetooth Core Specification 1.0B through 5.2 may permit an unauthenticated nearby device to spoof the BD_ADDR of the peer device to complete pairing without knowledge of the PIN.
MEDIUM 5.4EPSS 0.88%
Does this matter?
Lower severity and a low EPSS score (0.88%). Track it; it rarely justifies an emergency change on its own.
Description
Bluetooth legacy BR/EDR PIN code pairing in Bluetooth Core Specification 1.0B through 5.2 may permit an unauthenticated nearby device to spoof the BD_ADDR of the peer device to complete pairing without knowledge of the PIN.
- CVSS 3.1
- 5.4 MEDIUMCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
- EPSS
- 0.88% probability · 57th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-863
- Affected
- bluetooth/bluetooth core specification · fedoraproject/fedora · intel/ax210 firmware · intel/ax201 firmware · intel/ax200 firmware · intel/ac 9560 firmware · intel/ac 9462 firmware · intel/ac 9461 firmware · intel/ac 9260 firmware · intel/ac 8265 firmware · intel/ac 8260 firmware · intel/ac 3168 firmware · intel/ac 7265 firmware · intel/ac 3165 firmware · intel/killer wi-fi 6e ax1675 firmware · intel/killer wi-fi 6 ax1650 firmware · intel/killer ac 1550 firmware
- Source
- cve@mitre.org
References
- https://kb.cert.org/vuls/id/799380Third Party Advisory, US Government Resource
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NSS6CTGE4UGTJLCOZOASDR3T3SLL6QJZ/
- https://www.bluetooth.com/learn-about-bluetooth/key-attributes/bluetooth-security/reporting-security/Vendor Advisory
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00520.htmlThird Party Advisory
- https://kb.cert.org/vuls/id/799380Third Party Advisory, US Government Resource
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NSS6CTGE4UGTJLCOZOASDR3T3SLL6QJZ/
- https://www.bluetooth.com/learn-about-bluetooth/key-attributes/bluetooth-security/reporting-security/Vendor Advisory
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00520.htmlThird Party Advisory
- https://www.kb.cert.org/vuls/id/799380
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.