CVE-2020-26558

Aliases:UBUNTU-CVE-2020-26558DEBIAN-CVE-2020-26558
Advisory lineage Upstream: 0 Downstream: 40
Modified
Published: 24 May 2021, 17:22
Last modified:04 Nov 2025, 19:12

Vulnerability Summary

Overall Risk (default)
low
17/100
CVSS Score
4.3 MEDIUM
v2.0 (nvd)
EPSS Score
0.87% LOW
1% probability +0.85%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

24 May 2021, 17:22
Published
Vulnerability first disclosed
04 Nov 2025, 19:12
Last Modified
Vulnerability information updated

Description

Bluetooth LE and BR/EDR secure pairing in Bluetooth Core Specification 2.1 through 5.2 may permit a nearby man-in-the-middle attacker to identify the Passkey used during pairing (in the Passkey authentication procedure) by reflection of the public key and the authentication evidence of the initiating device, potentially permitting this attacker to complete authenticated pairing with the responding device using the correct Passkey for the pairing session. The attack methodology determines the Passkey value one bit at a time.

CVSS Metrics

  • v3.1MEDIUMScore: 4.2CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
  • v2.0MEDIUMScore: 4.3AV:A/AC:M/Au:N/C:P/I:P/A:N

EPSS Trends

Current EPSS score: 0.87% Percentile: 57%

Techniques & Countermeasures

  • CWE-287Improper Authentication

    When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Systems

  • bluetoothbluetooth_core_specification

    ≥ 2.1, ≤ 5.2

  • debianbluez

    < 5.55-3.1 | < 5.55-3.1 | < 5.55-3.1 | < 5.55-3.1

  • debianlinux

    < 5.10.40-1 | < 5.10.40-1 | < 5.10.40-1 | < 5.10.40-1

  • ubuntubluez

    < 5.37-0ubuntu5.3+esm1 | < 5.48-0ubuntu3.5 | < 5.53-0ubuntu3.2

  • ubuntulinux

    all | < 4.4.0-219.252 | < 4.15.0-151.157 | < 5.4.0-80.90

  • ubuntulinux-aws

    < 4.4.0-1099.104 | < 4.4.0-1135.149 | < 4.15.0-1109.116 | < 5.4.0-1054.57

  • ubuntulinux-aws-5.0

    all

  • ubuntulinux-aws-5.11

    < 5.11.0-1016.17~20.04.1

  • ubuntulinux-aws-5.3

    all

  • ubuntulinux-aws-5.4

    < 5.4.0-1054.57~18.04.1

  • ubuntulinux-aws-5.8

    < 5.8.0-1042.44~20.04.1

  • ubuntulinux-aws-fips

    < 4.15.0-2051.53 | all | < 5.4.0-1069.73+fips2

  • ubuntulinux-aws-hwe

    < 4.15.0-1109.116~16.04.1

  • ubuntulinux-azure

    < 4.15.0-1121.134~14.04.1 | < 4.15.0-1121.134~16.04.1 | all | < 5.4.0-1055.57

  • ubuntulinux-azure-4.15

    < 4.15.0-1121.134

  • ubuntulinux-azure-5.11

    < 5.11.0-1013.14~20.04.1

  • ubuntulinux-azure-5.3

    all

  • ubuntulinux-azure-5.4

    < 5.4.0-1055.57~18.04.1

  • ubuntulinux-azure-5.8

    < 5.8.0-1040.43~20.04.1

  • ubuntulinux-azure-edge

    all

  • ubuntulinux-azure-fde-5.15

    < 5.15.0-1114.123~20.04.1

  • ubuntulinux-azure-fips

    < 4.15.0-2033.37 | all | < 5.4.0-1073.76+fips1

  • ubuntulinux-bluefield

    all | < 5.4.0-1016.19

  • ubuntulinux-dell300x

    < 4.15.0-1027.32

  • ubuntulinux-fips

    < 4.4.0-1069.75 | all | < 4.15.0-1066.75 | < 5.4.0-1031.36

  • ubuntulinux-gcp

    < 4.15.0-1106.120~16.04.1 | all | < 5.4.0-1049.53

  • ubuntulinux-gcp-4.15

    < 4.15.0-1106.120

  • ubuntulinux-gcp-5.11

    < 5.11.0-1017.19~20.04.1

  • ubuntulinux-gcp-5.3

    all

  • ubuntulinux-gcp-5.4

    < 5.4.0-1049.53~18.04.1

  • ubuntulinux-gcp-5.8

    < 5.8.0-1039.41

  • ubuntulinux-gcp-edge

    all

  • ubuntulinux-gcp-fips

    < 4.15.0-2016.18 | all | < 5.4.0-1067.71~20.04.1

  • ubuntulinux-gke

    < 5.4.0-1049.52

  • ubuntulinux-gke-4.15

    all

  • ubuntulinux-gke-5.4

    < 5.4.0-1049.52~18.04.1

  • ubuntulinux-gkeop

    < 5.4.0-1021.22

  • ubuntulinux-gkeop-5.4

    < 5.4.0-1021.22~18.04.1

  • ubuntulinux-hwe

    < 4.15.0-151.157~16.04.1 | all

  • ubuntulinux-hwe-5.11

    < 5.11.0-34.36~20.04.1

  • ubuntulinux-hwe-5.4

    < 5.4.0-80.90~18.04.1

  • ubuntulinux-hwe-5.8

    all

  • ubuntulinux-hwe-edge

    all | all

  • ubuntulinux-intel-iot-realtime

    all

  • ubuntulinux-kvm

    < 4.4.0-1100.109 | < 4.15.0-1097.99 | < 5.4.0-1044.46

  • ubuntulinux-lts-xenial

    < 4.4.0-219.252~14.04.1

  • ubuntulinux-oem

    all

  • ubuntulinux-oem-5.10

    < 5.10.0-1032.33

  • ubuntulinux-oem-5.6

    all

  • ubuntulinux-oracle

    < 4.15.0-1078.86~16.04.1 | < 4.15.0-1078.86 | < 5.4.0-1052.56

Showing first 50 affected entries in server-rendered view.

References (23)