Legacy pairing and secure-connections pairing authentication in Bluetooth BR/EDR Core Specification v5.2 and earlier may allow an unauthenticated user to complete authentication without pairing credentials via adjacent access. An unauthenticated, adjacent attacker could impersonate a Bluetooth BR/EDR master or slave to pair with a previously paired remote device to successfully complete the authentication procedure without knowing the link key.
2020-05-19T16:15:11.073
2024-11-21T04:54:53.243
Modified
CVSSv3.1: 5.4 (MEDIUM)
AV:A/AC:L/Au:N/C:P/I:P/A:N
6.5
4.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | bluetooth | bluetooth_core | ≤ 5.2 | Yes |
Application | bluetooth | bluetooth_core | ≤ 5.2 | Yes |
Operating System | opensuse | leap | 15.1 | Yes |