CVE-2022-20361
CRITICALAndroid - Remote Privilege Escalation via Bluetooth Cross-Transport Key Derivation Weakness
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2022-20361. PoCs published by francozappa.
AI-analyzed exploit summary This repository contains a proof-of-concept for the BLURtooth attack (CVE-2020-15802), which exploits Cross-Transport Key Derivation (CTKD) in Bluetooth Classic and Bluetooth Low Energy. The PoC demonstrates how an attacker can impersonate a device and overwrite pairing keys by downgrading the pairing procedure to Just Works.
Description
In btif_dm_auth_cmpl_evt of btif_dm.cc, there is a possible vulnerability in Cross-Transport Key Derivation due to Weakness in Bluetooth Standard. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-231161832
Exploits (1)
This repository contains a proof-of-concept for the BLURtooth attack (CVE-2020-15802), which exploits Cross-Transport Key Derivation (CTKD) in Bluetooth Classic and Bluetooth Low Energy. The PoC demonstrates how an attacker can impersonate a device and overwrite pairing keys by downgrading the pairing procedure to Just Works.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H