CVE-2020-26558

Advisory lineage Upstream: 0 Downstream: 40
Modified
Published: 24 May 2021, 17:22
Last modified:04 Nov 2025, 19:12

Vulnerability Summary

Overall Risk (default)
low
17/100
CVSS Score
4.3 MEDIUM
v2.0 (nvd)
EPSS Score
0.02% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

24 May 2021, 17:22
Published
Vulnerability first disclosed
04 Nov 2025, 19:12
Last Modified
Vulnerability information updated

Description

Bluetooth LE and BR/EDR secure pairing in Bluetooth Core Specification 2.1 through 5.2 may permit a nearby man-in-the-middle attacker to identify the Passkey used during pairing (in the Passkey authentication procedure) by reflection of the public key and the authentication evidence of the initiating device, potentially permitting this attacker to complete authenticated pairing with the responding device using the correct Passkey for the pairing session. The attack methodology determines the Passkey value one bit at a time.

CVSS Metrics

  • v3.1MEDIUMScore: 4.2CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
  • v2.0MEDIUMScore: 4.3AV:A/AC:M/Au:N/C:P/I:P/A:N

EPSS Trends

Current EPSS score: 0.02% Percentile: 7%

Techniques & Countermeasures

  • CWE-287Improper Authentication

    When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Systems

  • bluetoothbluetooth_core_specification

    ≥ 2.1, ≤ 5.2

  • debiandebian_linux

    9.0

  • fedoraprojectfedora

    34

  • intelac_1550_firmware

    na

  • intelac_3165_firmware

    na

  • intelac_3168_firmware

    na

  • intelac_7265_firmware

    na

  • intelac_8260_firmware

    na

  • intelac_8265_firmware

    na

  • intelac_9260_firmware

    na

  • intelac_9461_firmware

    na

  • intelac_9462_firmware

    na

  • intelac_9560_firmware

    na

  • intelax1650_firmware

    na

  • intelax1675_firmware

    na

  • intelax200_firmware

    na

  • intelax201_firmware

    na

  • intelax210_firmware

    na

  • linuxlinux_kernel

    < 5.13

References (11)