CVE-2021-1683
MEDIUMWindows 10 - Bluetooth Passkey Entry Protocol Impersonation
Title source: llmDescription
Microsoft is aware of the "Impersonation in the Passkey Entry Protocol" vulnerability. For more information regarding the vulnerability, please see this statement from the Bluetooth SIG. To address the vulnerability, Microsoft has released a software update that will fail attempts to pair if the remote device exchanges a public key with the same X coordinate as the locally exchanged public key
References (2)
Core 2
Core References
Vendor Advisory vendor-advisory
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-1683
Scores
CVSS v3
5.0
EPSS
0.0165
EPSS Percentile
74.1%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
Details
Status
published
Products (15)
microsoft/windows_10
microsoft/windows_10
20h2
microsoft/windows_10
1607
microsoft/windows_10
1803
microsoft/windows_10
1809
microsoft/windows_10
1909
microsoft/windows_10
2004
microsoft/windows_8.1
microsoft/windows_rt_8.1
microsoft/windows_server_2012
r2
... and 5 more
Published
Jan 12, 2021
Tracked Since
Feb 18, 2026