CVE-2020-26555

MEDIUM

Bluetooth Core Specification <5.2 - Unauthenticated Spoofing

Title source: llm
STIX 2.1

Description

Bluetooth legacy BR/EDR PIN code pairing in Bluetooth Core Specification 1.0B through 5.2 may permit an unauthenticated nearby device to spoof the BD_ADDR of the peer device to complete pairing without knowledge of the PIN.

References (5)

Core 5
Core References
Third Party Advisory, US Government Resource x_refsource_misc
https://kb.cert.org/vuls/id/799380
Third Party Advisory, US Government Resource
https://www.kb.cert.org/vuls/id/799380

Scores

CVSS v3 5.4
EPSS 0.0012
EPSS Percentile 31.0%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Details

CWE
CWE-863
Status published
Products (17)
bluetooth/bluetooth_core_specification 1.1b - 5.2
fedoraproject/fedora 34
intel/ac_3165_firmware
intel/ac_3168_firmware
intel/ac_7265_firmware
intel/ac_8260_firmware
intel/ac_8265_firmware
intel/ac_9260_firmware
intel/ac_9461_firmware
intel/ac_9462_firmware
... and 7 more
Published May 24, 2021
Tracked Since Feb 18, 2026