bluez: BLESA bluetooth attack
Published Apr 1, 2020
6.6
MEDIUMCVSS 3.1
EPSS 1.19%
Description
A logic issue was addressed with improved state management. This issue is fixed in iOS 13.4 and iPadOS 13.4. An attacker in a privileged network position may be able to intercept Bluetooth traffic.
Affected products
-
- Version unspecifiedStatusaffectedConstraints<iOS 13.4 and iPadOS 13.4
- Version
No data.
Red Hat Enterprise Linux 7
bluez
Will not fix
Red Hat Enterprise Linux 8
bluez
Will not fix
Red Hat Enterprise Linux 9
bluez
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | bluez | Will not fix | n/a |
| Red Hat Enterprise Linux 8 | bluez | Will not fix | n/a |
| Red Hat Enterprise Linux 9 | bluez | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
The research paper describes that Bluetooth Low Energy connections managed through `bluetoothctl` control or via D-Bus API are not vulnerable to this attack as they strictly follow the proactive authentication specification. Connections that are managed by `gatttool` are among those that may be vulnerable.
Red Hat mitigation
Bluetooth Low Energy can be disabled altogether if it is not required, using the configuration below. This will prevent BLE devices from connecting with the host, disabling this attack ```ControllerMode=bredr```
References (6)
- https://access.redhat.com/security/cve/CVE-2020-9770 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1879820 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2020-9770
- https://support.apple.com/HT211102 x_refsource_MISCVendor Advisory
- https://www.cve.org/CVERecord?id=CVE-2020-9770
- https://www.usenix.org/system/files/woot20-paper-wu-updated.pdf
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2020-9770 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1879820 | Issue Tracking | |
| https://nvd.nist.gov/vuln/detail/CVE-2020-9770 | ||
| https://support.apple.com/HT211102 | x_refsource_MISCVendor Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2020-9770 | ||
| https://www.usenix.org/system/files/woot20-paper-wu-updated.pdf |
Change history (0)
No recorded changes yet.