VYPR
Unrated severityNVD Advisory· Published May 19, 2020· Updated Sep 17, 2024

Bluetooth devices supporting BR/EDR v5.2 and earlier are vulnerable to impersonation attacks

CVE-2020-10135

Description

Legacy pairing and secure-connections pairing authentication in Bluetooth BR/EDR Core Specification v5.2 and earlier may allow an unauthenticated user to complete authentication without pairing credentials via adjacent access. An unauthenticated, adjacent attacker could impersonate a Bluetooth BR/EDR master or slave to pair with a previously paired remote device to successfully complete the authentication procedure without knowing the link key.

Affected products

206

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

7

News mentions

0

No linked articles in our index yet.