cbcvebase.
CVE-2020-26558
published 2021-05-24

CVE-2020-26558: Bluetooth LE and BR/EDR secure pairing in Bluetooth Core Specification 2.1 through 5.2 may permit a nearby man-in-the-middle attacker to identify the Passkey…

PriorityP423medium4.2CVSS 3.1
AVAACHPRNUINSUCLILAN
EPSS
0.87%
54.8th percentile
Bluetooth LE and BR/EDR secure pairing in Bluetooth Core Specification 2.1 through 5.2 may permit a nearby man-in-the-middle attacker to identify the Passkey used during pairing (in the Passkey authentication procedure) by reflection of the public key and the authentication evidence of the initiating device, potentially permitting this attacker to complete authenticated pairing with the responding device using the correct Passkey for the pairing session. The attack methodology determines the Passkey value one bit at a time.

Affected

29 ranges· showing 25
VendorProductVersion rangeFixed in
bluetoothbluetooth_core_specification2.1 – 5.2
bluezbluez>= 0 < 5.55-3.15.55-3.1
bluezbluez>= 0 < 5.55-3.15.55-3.1
bluezbluez>= 0 < 5.55-3.15.55-3.1
bluezbluez>= 0 < 5.55-3.15.55-3.1
bluezbluez>= 0 < 5.48-0ubuntu3.55.48-0ubuntu3.5
bluezbluez>= 0 < 5.53-0ubuntu3.25.53-0ubuntu3.2
bluezbluez>= 0 < 5.37-0ubuntu5.3+esm15.37-0ubuntu5.3+esm1
debianbluez< bluez 5.55-3.1 (bookworm)bluez 5.55-3.1 (bookworm)
debiandebian_linux
debianlinux< bluez 5.55-3.1 (bookworm)bluez 5.55-3.1 (bookworm)
fedoraprojectfedora
googleandroid
linuxlinux_kernel< 5.135.13
linuxlinux_kernel>= 0 < 5.10.40-15.10.40-1
linuxlinux_kernel>= 0 < 5.10.40-15.10.40-1
linuxlinux_kernel>= 0 < 5.10.40-15.10.40-1
linuxlinux_kernel>= 0 < 5.10.40-15.10.40-1
linuxlinux_kernel>= 0 < 4.15.0-151.1574.15.0-151.157
linuxlinux_kernel>= 0 < 5.4.0-80.905.4.0-80.90
linuxlinux_kernel>= 0 < 4.4.0-222.2554.4.0-222.255
linuxlinux_kernel>= 0 < 4.4.0-219.2524.4.0-219.252
msrccbl_mariner_1.0_arm
msrccbl_mariner_1.0_x64
msrccm1_kernel_5.10.116.1-1_on_cbl_mariner_1.0

CVSS provenance

nvdv3.14.2MEDIUMCVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:A/AC:M/Au:N/C:P/I:P/A:N
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian4.2MEDIUM
vendor_msrc4.2MEDIUM
vendor_redhat4.2MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.