CVE-2020-26558

MEDIUMCVSS 4.2/10EPSS 0.87%

Last modified

CVE-2020-26558 is a medium-severity vulnerability rated 4.2/10 on the CVSS scale. Bluetooth LE and BR/EDR secure pairing in Bluetooth Core Specification 2.1 through 5.2 may permit a nearby man-in-the-middle attacker to identify the Passkey used during pairing (in the Passkey authentication procedure) by reflection of the public key and the authentication evidence of the initiating device, potentially permitting this attacker to complete authenticated pairing with the responding device using the correct Passkey for the pairing session. The attack methodology determines the Passkey value one bit at a time.. EPSS estimates a 0.87% chance of exploitation in the next 30 days.

Description

Bluetooth LE and BR/EDR secure pairing in Bluetooth Core Specification 2.1 through 5.2 may permit a nearby man-in-the-middle attacker to identify the Passkey used during pairing (in the Passkey authentication procedure) by reflection of the public key and the authentication evidence of the initiating device, potentially permitting this attacker to complete authenticated pairing with the responding device using the correct Passkey for the pairing session. The attack methodology determines the Passkey value one bit at a time.

Metrics

CVSS 3.1
4.2/10

CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N

EPSS Probability
0.87%

54.3th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
BluetoothBluetooth Core Specification>= 2.1, <= 5.2
FedoraprojectFedora34
DebianDebian Linux9.0
LinuxLinux Kernel< 5.13
IntelAx210 FirmwareAll versions
IntelAx201 FirmwareAll versions
IntelAx200 FirmwareAll versions
IntelAc 9560 FirmwareAll versions
IntelAc 9462 FirmwareAll versions
IntelAc 9461 FirmwareAll versions
IntelAc 9260 FirmwareAll versions
IntelAc 8265 FirmwareAll versions
IntelAc 8260 FirmwareAll versions
IntelAc 3168 FirmwareAll versions
IntelAc 7265 FirmwareAll versions
IntelAc 3165 FirmwareAll versions
IntelAx1675 FirmwareAll versions
IntelAx1650 FirmwareAll versions
IntelAc 1550 FirmwareAll versions

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2020-26558?
Bluetooth LE and BR/EDR secure pairing in Bluetooth Core Specification 2.1 through 5.2 may permit a nearby man-in-the-middle attacker to identify the Passkey used during pairing (in the Passkey authentication procedure) by reflection of the public key and the authentication evidence of the initiating device, potentially permitting this attacker to complete authenticated pairing with the responding device using the correct Passkey for the pairing session. The attack methodology determines the Passkey value one bit at a time.
How severe is CVE-2020-26558?
CVE-2020-26558 has a CVSS score of 4.2/10 (MEDIUM severity). The EPSS model estimates a 0.87% probability of exploitation in the next 30 days.
How do I fix CVE-2020-26558?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2020-26558?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST