Back

MEDIUM

Bluetooth devices supporting BR/EDR v5.2 and earlier are vulnerable to impersonation attacks

Published May 19, 2020

Description

Legacy pairing and secure-connections pairing authentication in Bluetooth BR/EDR Core Specification v5.2 and earlier may allow an unauthenticated user to complete authentication without pairing credentials via adjacent access. An unauthenticated, adjacent attacker could impersonate a Bluetooth BR/EDR master or slave to pair with a previously paired remote device to successfully complete the authentication procedure without knowing the link key.

Affected products

Remediation

Red Hat mitigation

Enforce the Secure Connections Only mode for implementations that do not require support for pairing with legacy devices. Disabling Bluetooth may be a suitable alternative for some environments, please refer to the Red Hat knowledgebase solution [1] for how to disable Bluetooth in Red Hat Enterprise Linux. [1] https://access.redhat.com/solutions/2682931

Metrics

References (11)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner certcc
Published May 19, 2020
Updated Sep 17, 2024
Reserved Mar 5, 2020
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date May 18, 2020