CVE-2020-9770
published 2020-04-01CVE-2020-9770: A logic issue was addressed with improved state management. This issue is fixed in iOS 13.4 and iPadOS 13.4. An attacker in a privileged network position may…
PriorityP433medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
1.19%
64.7th percentile
A logic issue was addressed with improved state management. This issue is fixed in iOS 13.4 and iPadOS 13.4. An attacker in a privileged network position may be able to intercept Bluetooth traffic.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios | >= unspecified < iOS 13.4 and iPadOS 13.4 | iOS 13.4 and iPadOS 13.4 |
| apple | ipados | < 13.4 | 13.4 |
| apple | iphone_os | < 13.4 | 13.4 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
osv6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-f9h7-x4m7-p8mw: A logic issue was addressed with improved state management
ghsa_unreviewed·2022-05-24
CVE-2020-9770 [MEDIUM] CWE-326 GHSA-f9h7-x4m7-p8mw: A logic issue was addressed with improved state management
A logic issue was addressed with improved state management. This issue is fixed in iOS 13.4 and iPadOS 13.4. An attacker in a privileged network position may be able to intercept Bluetooth traffic.
OSV
CVE-2020-9770: A logic issue was addressed with improved state management
osv·2020-04-01·CVSS 6.5
CVE-2020-9770 [MEDIUM] CVE-2020-9770: A logic issue was addressed with improved state management
A logic issue was addressed with improved state management. This issue is fixed in iOS 13.4 and iPadOS 13.4. An attacker in a privileged network position may be able to intercept Bluetooth traffic.
Red Hat
bluez: BLESA bluetooth attack
vendor_redhat·2020-09-15·CVSS 6.5
CVE-2020-9770 [MEDIUM] CWE-305 bluez: BLESA bluetooth attack
bluez: BLESA bluetooth attack
A logic issue was addressed with improved state management. This issue is fixed in iOS 13.4 and iPadOS 13.4. An attacker in a privileged network position may be able to intercept Bluetooth traffic.
Statement: The research paper describes that Bluetooth Low Energy connections managed through `bluetoothctl` control or via D-Bus API are not vulnerable to this attack as they strictly follow the proactive authentication specification. Connections that are managed by `gatttool` are among those that may be vulnerable.
Mitigation: Bluetooth Low Energy can be disabled altogether if it is not required, using the configuration below. This will prevent BLE devices from connecting with the host, disabling this attack
```ControllerMode=bredr```
Package: bluez (Red Hat E
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-9770 bluez: BLESA bluetooth attack [fedora-all]
bugzilla·2020-09-24·CVSS 6.5
CVE-2020-9770 [MEDIUM] CVE-2020-9770 bluez: BLESA bluetooth attack [fedora-all]
CVE-2020-9770 bluez: BLESA bluetooth attack [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. While onl
Bugzilla
CVE-2020-9770 bluez: BLESA bluetooth attack
bugzilla·2020-09-17·CVSS 6.5
CVE-2020-9770 [MEDIUM] CVE-2020-9770 bluez: BLESA bluetooth attack
CVE-2020-9770 bluez: BLESA bluetooth attack
An authentication bypass in the Bluetooth Low Energy (BLE) protocol could enable physically proximate attackers to impersonate trusted bluetooth devices.
External references:
https://www.usenix.org/system/files/woot20-paper-wu-updated.pdf
Discussion:
Statement:
The research paper describes that Bluetooth Low Energy connections managed through `bluetoothctl` control or via D-Bus API are not vulnerable to this attack as they strictly follow the proactive authentication specification. Connections that are managed by `gatttool` are among those that may be vulnerable.
---
Mitigation:
Bluetooth Low Energy can be disabled altogether if it is not required, using the configuration below. This will prevent BLE devices from connecting with the host
2020-04-01
Published