CVE-2014-7914

HIGH

Android < 5.1 - Incorrect Authorization via Bluetooth Pairing Bypass

Title source: llm
STIX 2.1

Description

btif/src/btif_dm.c in Android before 5.1 does not properly enforce the temporary nature of a Bluetooth pairing, which allows user-assisted remote attackers to bypass intended access restrictions via crafted Bluetooth packets after the tapping of a crafted NFC tag.

References (1)

Core 1

Scores

CVSS v3 8.1
EPSS 0.0047
EPSS Percentile 37.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

Details

CWE
CWE-863
Status published
Products (1)
google/android < 5.1
Published Feb 21, 2020
Tracked Since Feb 18, 2026