CVE-2020-26558 describes a man-in-the-middle vulnerability in Bluetooth Core Specification versions 2.1 through 5.2, affecting products like Linux, Intel, and Debian. This flaw allows a nearby attacker to deduce the Passkey during secure pairing by reflecting public keys and authentication evidence. The vulnerability has a CVSS score of 4.2 (MEDIUM), indicating an adjacent attack vector with high attack complexity, potentially leading to low confidentiality and integrity impacts. While there are no known active exploits or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community discussion and media coverage, suggesting awareness despite its inactive status on hot lists.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.1, <= 5.2CPE matchmatch criteria | cpe:2.3:a:bluetooth:bluetooth_core_specification:*:*:*:*:*:*:*:* | ||
34CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* | ||
< 5.13CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:intel:ax210_firmware:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2020-26558
Apr 12, 2022bluez: Passkey Entry protocol of the Bluetooth Core is vulnerable to an impersonation attack
May 24, 2021Bluetooth LE and BR/EDR secure pairing in Bluetooth Core Specification 2.1 through 5.2 may permit a nearby man-in-the-middle attacker to identify the Passkey used during pairing (in the Passkey authentication procedure) by reflection of the public key and the authentication evidence of the initiating device potentially permitting this attacker to complete authenticated pairing with the responding device using the correct Passkey for the pairing session. The attack methodology determines the Passkey value one bit at a time.
May 11, 2021