CVE-2020-26555

MEDIUMCVSS 5.4/10EPSS 0.89%

Last modified

CVE-2020-26555 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. Bluetooth legacy BR/EDR PIN code pairing in Bluetooth Core Specification 1.0B through 5.2 may permit an unauthenticated nearby device to spoof the BD_ADDR of the peer device to complete pairing without knowledge of the PIN.. EPSS estimates a 0.89% chance of exploitation in the next 30 days.

Description

Bluetooth legacy BR/EDR PIN code pairing in Bluetooth Core Specification 1.0B through 5.2 may permit an unauthenticated nearby device to spoof the BD_ADDR of the peer device to complete pairing without knowledge of the PIN.

Metrics

CVSS 3.1
5.4/10

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

EPSS Probability
0.89%

54.7th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
BluetoothBluetooth Core Specification>= 1.1b, <= 5.2
FedoraprojectFedora34
IntelAx210 FirmwareAll versions
IntelAx201 FirmwareAll versions
IntelAx200 FirmwareAll versions
IntelAc 9560 FirmwareAll versions
IntelAc 9462 FirmwareAll versions
IntelAc 9461 FirmwareAll versions
IntelAc 9260 FirmwareAll versions
IntelAc 8265 FirmwareAll versions
IntelAc 8260 FirmwareAll versions
IntelAc 3168 FirmwareAll versions
IntelAc 7265 FirmwareAll versions
IntelAc 3165 FirmwareAll versions
IntelKiller Wi-Fi 6e Ax1675 FirmwareAll versions
IntelKiller Wi-Fi 6 Ax1650 FirmwareAll versions
IntelKiller Ac 1550 FirmwareAll versions

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2020-26555?
Bluetooth legacy BR/EDR PIN code pairing in Bluetooth Core Specification 1.0B through 5.2 may permit an unauthenticated nearby device to spoof the BD_ADDR of the peer device to complete pairing without knowledge of the PIN.
How severe is CVE-2020-26555?
CVE-2020-26555 has a CVSS score of 5.4/10 (MEDIUM severity). The EPSS model estimates a 0.89% probability of exploitation in the next 30 days.
How do I fix CVE-2020-26555?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2020-26555?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST