cbcvebase.
CVE-2020-15802
published 2020-09-11

CVE-2020-15802: Devices supporting Bluetooth before 5.1 may allow man-in-the-middle attacks, aka BLURtooth. Cross Transport Key Derivation in Bluetooth Core Specification v4.2…

PriorityP337medium5.9CVSS 3.1
AVNACHPRNUINSUCNIHAN
EPSS
7.14%
93.6th percentile
Devices supporting Bluetooth before 5.1 may allow man-in-the-middle attacks, aka BLURtooth. Cross Transport Key Derivation in Bluetooth Core Specification v4.2 and v5.0 may permit an unauthenticated user to establish a bonding with one transport, either LE or BR/EDR, and replace a bonding already established on the opposing transport, BR/EDR or LE, potentially overwriting an authenticated key with an unauthenticated key, or a key with greater entropy with one with less.

Affected

7 ranges
VendorProductVersion rangeFixed in
bluetoothbluetooth_core_specification< 5.15.1
googleandroid
platformsystem_bt>= 10:0 < 10:2020-12-0110:2020-12-01
platformsystem_bt>= 11:0 < 11:2020-12-0111:2020-12-01
platformsystem_bt>= 8.0:0 < 8.0:2020-12-018.0:2020-12-01
platformsystem_bt>= 8.1:0 < 8.1:2020-12-018.1:2020-12-01
platformsystem_bt>= 9:0 < 9:2020-12-019:2020-12-01

Detection & IOCsextracted from sources · hover to see the quote

  • Monitor for unauthenticated Bluetooth pairing attempts (e.g., Just Works association) on one transport (LE or BR/EDR) that result in key derivation or key overwrite on the opposing transport via CTKD
  • Alert on Bluetooth pairing events where an existing authenticated or higher-entropy key is replaced by an unauthenticated or lower-entropy key across transports (BR/EDR ↔ LE)
  • Audit Android devices running AOSP 8.0, 8.1, 9, 10, or 11 for the BLURtooth/CTKD vulnerability (Android bug reference A-158854097)
  • Detect Bluetooth chips from Broadcom, CSR, Cypress, Intel, and Qualcomm supporting Bluetooth 4.2, 5.0, 5.1, or 5.2 (all CTKD-capable versions) as potentially vulnerable targets
  • ·The /etc/bluetooth/main.conf ControllerMode setting can restrict the Bluetooth controller to a single transport (bredr or le), eliminating the dual-mode attack surface; default is 'dual'
  • ·The Bluetooth SIG claimed Bluetooth 5.1 and later are not vulnerable, but the researchers found 5.1 and 5.2 devices to still be susceptible in practice
  • ·The attack does not require the attacker to be present during the original pairing event, unlike prior Bluetooth attacks, making passive detection of the initial pairing insufficient

CVSS provenance

nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv5.9MEDIUM
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.