5.4

CVE-2020-10135

Exploit

Bluetooth devices supporting BR/EDR v5.2 and earlier are vulnerable to impersonation attacks

Legacy pairing and secure-connections pairing authentication in Bluetooth BR/EDR Core Specification v5.2 and earlier may allow an unauthenticated user to complete authentication without pairing credentials via adjacent access. An unauthenticated, adjacent attacker could impersonate a Bluetooth BR/EDR master or slave to pair with a previously paired remote device to successfully complete the authentication procedure without knowing the link key.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Bluetooth ≫ Bluetooth Core SwEdition br Version <= 5.2
Bluetooth ≫ Bluetooth Core SwEdition edr Version <= 5.2
Opensuse ≫ Leap Version 15.1
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.39% 0.818
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.4 2.8 2.5
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
NIST 4.8 6.5 4.9
AV:A/AC:L/Au:N/C:P/I:P/A:N
CERT.org 5.4 2.8 2.5
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
CWE-290 Authentication Bypass by Spoofing

This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.

CWE-757 Selection of Less-Secure Algorithm During Negotiation ('Algorithm Downgrade')

A protocol or its implementation supports interaction between multiple actors and allows those actors to negotiate which algorithm should be used as a protection mechanism such as encryption or authentication, but it does not select the strongest algorithm that is available to both parties.

http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00009.html
Third Party Advisory
Broken Link
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00047.html
Third Party Advisory
Broken Link
Mailing List
http://packetstormsecurity.com/files/157922/Bluetooth-Impersonation-Attack-BIAS-Proof-Of-Concept.html
Third Party Advisory
VDB Entry
http://seclists.org/fulldisclosure/2020/Jun/5
Third Party Advisory
Exploit
Mailing List
https://francozappa.github.io/about-bias/
Third Party Advisory
https://kb.cert.org/vuls/id/647177/
Third Party Advisory
US Government Resource
https://www.bluetooth.com/learn-about-bluetooth/bluetooth-technology/bluetooth-security/bias-vulnerability/
Vendor Advisory