cbcvebase.
CVE-2020-10135
published 2020-05-19

CVE-2020-10135: Legacy pairing and secure-connections pairing authentication in Bluetooth BR/EDR Core Specification v5.2 and earlier may allow an unauthenticated user to…

medium5.4CVSS 3.1
AVAACLPRNUINSUCLILAN
Legacy pairing and secure-connections pairing authentication in Bluetooth BR/EDR Core Specification v5.2 and earlier may allow an unauthenticated user to complete authentication without pairing credentials via adjacent access. An unauthenticated, adjacent attacker could impersonate a Bluetooth BR/EDR master or slave to pair with a previously paired remote device to successfully complete the authentication procedure without knowing the link key.

Affected

11 ranges
VendorProductVersion rangeFixed in
appleios
applemacos_mojave_10.14.6_security_update_2019-004_high_sierra_security_update_2019-0
appletvos
applewatchos
bluetoothbluetooth_core<= 5.2
bluetoothbr_edr5.2 – 5.2
linuxlinux_kernel>= 0 < 4.4.0-197.2294.4.0-197.229
linuxlinux_kernel>= 0 < 4.15.0-129.1324.15.0-129.132
linuxlinux_kernel>= 0 < 5.4.0-58.645.4.0-58.64
linuxlinux_kernel>= 0 < 5.4.0-56.625.4.0-56.62
opensuseleap

CVSS provenance

nvdv3.15.4MEDIUMCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
osv8.2HIGH