imPC@ndo IT

Tracker / CVE-2020-26558

CVE-2020-26558

Medium 4.2

Bluetooth LE and BR/EDR secure pairing in Bluetooth Core Specification 2.1 through 5.2 may permit a nearby man-in-the-middle attacker to identify the Passkey used during pairing (in the Passkey authentication procedure) by reflection of the public key and the authentication evidence of the initiating device, potentially permitting this attacker to complete authenticated pairing with the responding device using the correct Passkey for the pairing session. The attack methodology determines the Passkey value one bit at a time.

Affected products and versions

bluetooth bluetooth_core_specification · 2.1 → 5.2
debian debian_linux
fedoraproject fedora
intel ac_1550_firmware
intel ac_3165_firmware
intel ac_3168_firmware
intel ac_7265_firmware
intel ac_8260_firmware
intel ac_8265_firmware
intel ac_9260_firmware
intel ac_9461_firmware
intel ac_9462_firmware
intel ac_9560_firmware
intel ax1650_firmware
intel ax1675_firmware
intel ax200_firmware
intel ax201_firmware
intel ax210_firmware
linux linux_kernel · … → 5.13

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References