CVE-2020-26558
Description
Bluetooth LE and BR/EDR secure pairing in Bluetooth Core Specification 2.1 through 5.2 may permit a nearby man-in-the-middle attacker to identify the Passkey used during pairing (in the Passkey authentication procedure) by reflection of the public key and the authentication evidence of the initiating device, potentially permitting this attacker to complete authenticated pairing with the responding device using the correct Passkey for the pairing session. The attack methodology determines the Passkey value one bit at a time.
Risk Information
Base Score
4.2
MODERATE
Vector
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
EPSS Score
Exploitation Probability
0.023
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| Bluetooth tools and daemons (USN-4989-1) bluez_5.48-0ubuntu3.5_i386.deb | Linux |
| Bluetooth tools and daemons (USN-4989-1) bluez_5.48-0ubuntu3.5_amd64.deb | Linux |
| Bluetooth tools and daemons (USN-4989-1) bluez_5.53-0ubuntu3.2_i386.deb | Linux |
| Bluetooth tools and daemons (USN-4989-1) bluez_5.53-0ubuntu3.2_amd64.deb | Linux |
| Bluetooth tools and daemons (USN-4989-1) bluez_5.55-0ubuntu1.2_i386.deb | Linux |
| Bluetooth tools and daemons (USN-4989-1) bluez_5.55-0ubuntu1.2_amd64.deb | Linux |
| Bluetooth tools and daemons (USN-4989-1) bluez_5.56-0ubuntu4.1_i386.deb | Linux |
| Bluetooth tools and daemons (USN-4989-1) bluez_5.56-0ubuntu4.1_amd64.deb | Linux |
| Bluetooth tools and daemons (USN-4989-1) libbluetooth3_5.48-0ubuntu3.5_i386.deb | Linux |
| Bluetooth tools and daemons (USN-4989-1) libbluetooth3_5.48-0ubuntu3.5_amd64.deb | Linux |
| Bluetooth tools and daemons (USN-4989-1) libbluetooth3_5.53-0ubuntu3.2_i386.deb | Linux |
| Bluetooth tools and daemons (USN-4989-1) libbluetooth3_5.53-0ubuntu3.2_amd64.deb | Linux |
| Bluetooth tools and daemons (USN-4989-1) libbluetooth3_5.55-0ubuntu1.2_i386.deb | Linux |
| Bluetooth tools and daemons (USN-4989-1) libbluetooth3_5.55-0ubuntu1.2_amd64.deb | Linux |
| Bluetooth tools and daemons (USN-4989-1) libbluetooth3_5.56-0ubuntu4.1_i386.deb | Linux |
| Bluetooth tools and daemons (USN-4989-1) libbluetooth3_5.56-0ubuntu4.1_amd64.deb | Linux |
| SUSE-SU-2021:2321-1(SUSE Linux Enterprise Server 12-SP5 ) kernel-azure-4.12.14-16.62.1.x86_64.rpm | Linux |
| SUSE-SU-2021:2321-1(SUSE Linux Enterprise Server 12-SP5 ) kernel-azure-base-4.12.14-16.62.1.x86_64.rpm | Linux |
| SUSE-SU-2021:2321-1(SUSE Linux Enterprise Server 12-SP5 ) kernel-azure-base-debuginfo-4.12.14-16.62.1.x86_64.rpm | Linux |
| SUSE-SU-2021:2321-1(SUSE Linux Enterprise Server 12-SP5 ) kernel-azure-debuginfo-4.12.14-16.62.1.x86_64.rpm | Linux |
| SUSE-SU-2021:2321-1(SUSE Linux Enterprise Server 12-SP5 ) kernel-azure-debugsource-4.12.14-16.62.1.x86_64.rpm | Linux |
| SUSE-SU-2021:2321-1(SUSE Linux Enterprise Server 12-SP5 ) kernel-azure-devel-4.12.14-16.62.1.x86_64.rpm | Linux |
| SUSE-SU-2021:2321-1(SUSE Linux Enterprise Server 12-SP5 ) kernel-devel-azure-4.12.14-16.62.1.noarch.rpm | Linux |
| SUSE-SU-2021:2321-1(SUSE Linux Enterprise Server 12-SP5 ) kernel-source-azure-4.12.14-16.62.1.noarch.rpm | Linux |
| SUSE-SU-2021:2321-1(SUSE Linux Enterprise Server 12-SP5 ) kernel-syms-azure-4.12.14-16.62.1.x86_64.rpm | Linux |
| Linux kernel (USN-5018-1) linux-image-kvm_4.15.0.1097.93_amd64.deb | Linux |
| Linux kernel (USN-5018-1) linux-image-generic_4.15.0.151.139_i386.deb | Linux |
| Linux kernel (USN-5018-1) linux-image-generic_4.15.0.151.139_amd64.deb | Linux |
| Linux kernel (USN-5018-1) linux-image-virtual_4.15.0.151.139_i386.deb | Linux |
| Linux kernel (USN-5018-1) linux-image-virtual_4.15.0.151.139_amd64.deb | Linux |
| Linux kernel (USN-5018-1) linux-image-lowlatency_4.15.0.151.139_i386.deb | Linux |
| Linux kernel (USN-5018-1) linux-image-lowlatency_4.15.0.151.139_amd64.deb | Linux |
| Linux kernel (USN-5018-1) linux-image-aws-lts-18.04_4.15.0.1109.112_amd64.deb | Linux |
| Linux kernel (USN-5018-1) linux-image-gcp-lts-18.04_4.15.0.1106.125_amd64.deb | Linux |
| Linux kernel (USN-5018-1) linux-image-4.15.0-1097-kvm_4.15.0-1097.99_amd64.deb | Linux |
| Linux kernel (USN-5018-1) linux-image-4.15.0-1106-gcp_4.15.0-1106.120_amd64.deb | Linux |
| Linux kernel (USN-5018-1) linux-image-4.15.0-1109-aws_4.15.0-1109.116_amd64.deb | Linux |
| Linux kernel (USN-5018-1) linux-image-azure-lts-18.04_4.15.0.1121.94_amd64.deb | Linux |
| Linux kernel (USN-5018-1) linux-image-oracle-lts-18.04_4.15.0.1078.88_amd64.deb | Linux |
| Linux kernel (USN-5018-1) linux-image-4.15.0-1121-azure_4.15.0-1121.134_amd64.deb | Linux |
| Linux kernel (USN-5018-1) linux-image-4.15.0-1078-oracle_4.15.0-1078.86_amd64.deb | Linux |
| Linux kernel (USN-5018-1) linux-image-4.15.0-151-generic_4.15.0-151.157_i386.deb | Linux |
| Linux kernel (USN-5018-1) linux-image-4.15.0-151-generic_4.15.0-151.157_amd64.deb | Linux |
| Linux kernel (USN-5018-1) linux-image-4.15.0-151-lowlatency_4.15.0-151.157_i386.deb | Linux |
| Linux kernel (USN-5018-1) linux-image-4.15.0-151-lowlatency_4.15.0-151.157_amd64.deb | Linux |
| bluez security update(DSA-4951-1) bluez_5.50-1.2~deb10u2_i386.deb | Linux |
| bluez security update(DSA-4951-1) bluez_5.50-1.2~deb10u2_amd64.deb | Linux |
| Linux kernel (USN-5046-1) linux-image-aws_5.11.0.1016.17_amd64.deb | Linux |
| Linux kernel (USN-5046-1) linux-image-gcp_5.11.0.1017.17_amd64.deb | Linux |
| Linux kernel (USN-5046-1) linux-image-gke_5.11.0.1017.17_amd64.deb | Linux |
| Linux kernel (USN-5046-1) linux-image-azure_5.11.0.1013.14_amd64.deb | Linux |
| Linux kernel (USN-5046-1) linux-image-oracle_5.11.0.1016.17_amd64.deb | Linux |
| Linux kernel (USN-5046-1) linux-image-generic_5.11.0.31.33_amd64.deb | Linux |
| Linux kernel (USN-5046-1) linux-image-virtual_5.11.0.31.33_amd64.deb | Linux |
| Linux kernel (USN-5046-1) linux-image-oem-20.04_5.11.0.31.33_amd64.deb | Linux |
| Linux kernel (USN-5046-1) linux-image-lowlatency_5.11.0.31.33_amd64.deb | Linux |
| Linux kernel (USN-5046-1) linux-image-5.11.0-1016-aws_5.11.0-1016.17_amd64.deb | Linux |
| Linux kernel (USN-5046-1) linux-image-5.11.0-1017-gcp_5.11.0-1017.19_amd64.deb | Linux |
| Linux kernel (USN-5046-1) linux-image-5.11.0-1013-azure_5.11.0-1013.14_amd64.deb | Linux |
| Linux kernel (USN-5046-1) linux-image-5.11.0-27-generic_5.11.0-27.29~20.04.1_amd64.deb | Linux |
| Linux kernel (USN-5046-1) linux-image-5.11.0-31-generic_5.11.0-31.33_amd64.deb | Linux |
| Linux kernel (USN-5046-1) linux-image-generic-hwe-20.04_5.11.0.27.29~20.04.11_amd64.deb | Linux |
| Linux kernel (USN-5046-1) linux-image-virtual-hwe-20.04_5.11.0.27.29~20.04.11_amd64.deb | Linux |
| Linux kernel (USN-5046-1) linux-image-5.11.0-1016-oracle_5.11.0-1016.17_amd64.deb | Linux |
| Linux kernel (USN-5046-1) linux-image-5.11.0-27-lowlatency_5.11.0-27.29~20.04.1_amd64.deb | Linux |
| Linux kernel (USN-5046-1) linux-image-5.11.0-31-lowlatency_5.11.0-31.33_amd64.deb | Linux |
| Linux kernel (USN-5046-1) linux-image-lowlatency-hwe-20.04_5.11.0.27.29~20.04.11_amd64.deb | Linux |
| Linux kernel for Amazon Web Services (AWS) systems (USN-5050-1) linux-image-aws_5.8.0.1042.44~20.04.14_amd64.deb | Linux |
| Linux kernel for Amazon Web Services (AWS) systems (USN-5050-1) linux-image-gcp_5.8.0.1039.14_amd64.deb | Linux |
| Linux kernel for Amazon Web Services (AWS) systems (USN-5050-1) linux-image-azure_5.8.0.1040.43~20.04.12_amd64.deb | Linux |
| Linux kernel for Amazon Web Services (AWS) systems (USN-5050-1) linux-image-oracle_5.8.0.1038.39~20.04.14_amd64.deb | Linux |
| Linux kernel for Amazon Web Services (AWS) systems (USN-5050-1) linux-image-5.8.0-1039-gcp_5.8.0-1039.41_amd64.deb | Linux |
| Linux kernel for Amazon Web Services (AWS) systems (USN-5050-1) linux-image-5.8.0-1042-aws_5.8.0-1042.44~20.04.1_amd64.deb | Linux |
| Linux kernel for Amazon Web Services (AWS) systems (USN-5050-1) linux-image-5.8.0-1040-azure_5.8.0-1040.43~20.04.1_amd64.deb | Linux |
| Linux kernel for Amazon Web Services (AWS) systems (USN-5050-1) linux-image-5.8.0-1038-oracle_5.8.0-1038.39~20.04.1_amd64.deb | Linux |
| Bluez update (ELSA-2021-4432) bluez-5.56-1.el8.x86_64.rpm | Linux |
| Bluez-cups update (ELSA-2021-4432) bluez-cups-5.56-1.el8.x86_64.rpm | Linux |
| Bluez-hid2hci update (ELSA-2021-4432) bluez-hid2hci-5.56-1.el8.x86_64.rpm | Linux |
| Bluez-libs update (ELSA-2021-4432) bluez-libs-5.56-1.el8.i686.rpm | Linux |
| Bluez-libs update (ELSA-2021-4432) bluez-libs-5.56-1.el8.x86_64.rpm | Linux |
| Bluez-libs-devel update (ELSA-2021-4432) bluez-libs-devel-5.56-1.el8.i686.rpm | Linux |
| Bluez-libs-devel update (ELSA-2021-4432) bluez-libs-devel-5.56-1.el8.x86_64.rpm | Linux |
| Bluez-obexd update (ELSA-2021-4432) bluez-obexd-5.56-1.el8.x86_64.rpm | Linux |
| kernel Security Update (ALAS-2021-1685) kernel-livepatch-4.14.238-182.421-1.0-0.amzn2.x86_64.rpm | Linux |
Patch Details
No records foundReferences
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234