First published: Thu Jan 21 2021(Updated: )
A vulnerability was found in Linux Kernel, where Bluetooth BR/EDR PIN Pairing procedure is vulnerable to an impersonation attack. When an attacker connects to a victim device using the address of the device and the victim initiates a Pairing, the attacker can reflect the encrypted nonce even without knowledge of the key.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Android | ||
Bluetooth Core Specification | >=1.1b<=5.2 | |
Red Hat Fedora | =34 | |
Intel Wi-Fi 6E AX210 firmware | ||
Intel Wi-Fi 6 AX210 | ||
Intel Wi-Fi 6E AX201 Firmware | ||
Intel AX201 Firmware | ||
Intel AX200 Firmware | ||
Intel AX200 Firmware | ||
Intel AC 9560 Firmware | ||
Intel Wireless-AC 9560 | ||
Intel PROSet AC 9462 Firmware | ||
Intel ProSet AC 9462 | ||
Intel PROSet AC 9461 Firmware | ||
Intel ProSet AC 9461 | ||
Intel ProSet AC 9260 Firmware | ||
Intel PROSet Wireless for AC 9260 | ||
Intel ProSet AC 8265 Firmware | ||
Intel AC 8265 Firmware | ||
Intel ProSet Wireless Software and Drivers for Ac 8260 | ||
Intel PROSet AC 8260 | ||
Intel AC3168 Firmware | ||
Intel AC 3168 Firmware | ||
Intel AC 7265 | ||
Intel AC 7265 Firmware | ||
Intel PROSet/Wireless Software for Intel Dual Band Wireless-AC 3165 | ||
Intel AC 3165 Firmware | ||
Intel AX1675 Firmware | ||
Intel Killer Wi-Fi 6E AX1675 Firmware | ||
Intel AX1650 Firmware | ||
Intel Killer Wi-Fi 6 AX1650i/S | ||
Intel Killer Wireless-AC 1550 | ||
Intel Killer Wireless-AC 1550 | ||
All of | ||
Intel Wi-Fi 6E AX210 firmware | ||
Intel Wi-Fi 6 AX210 | ||
All of | ||
Intel Wi-Fi 6E AX201 Firmware | ||
Intel AX201 Firmware | ||
All of | ||
Intel AX200 Firmware | ||
Intel AX200 Firmware | ||
All of | ||
Intel AC 9560 Firmware | ||
Intel Wireless-AC 9560 | ||
All of | ||
Intel PROSet AC 9462 Firmware | ||
Intel ProSet AC 9462 | ||
All of | ||
Intel PROSet AC 9461 Firmware | ||
Intel ProSet AC 9461 | ||
All of | ||
Intel ProSet AC 9260 Firmware | ||
Intel PROSet Wireless for AC 9260 | ||
All of | ||
Intel ProSet AC 8265 Firmware | ||
Intel AC 8265 Firmware | ||
All of | ||
Intel ProSet Wireless Software and Drivers for Ac 8260 | ||
Intel PROSet AC 8260 | ||
All of | ||
Intel AC3168 Firmware | ||
Intel AC 3168 Firmware | ||
All of | ||
Intel AC 7265 | ||
Intel AC 7265 Firmware | ||
All of | ||
Intel PROSet/Wireless Software for Intel Dual Band Wireless-AC 3165 | ||
Intel AC 3165 Firmware | ||
All of | ||
Intel AX1675 Firmware | ||
Intel Killer Wi-Fi 6E AX1675 Firmware | ||
All of | ||
Intel AX1650 Firmware | ||
Intel Killer Wi-Fi 6 AX1650i/S | ||
All of | ||
Intel Killer Wireless-AC 1550 | ||
Intel Killer Wireless-AC 1550 | ||
IBM Security Verify Governance - Identity Manager | <=ISVG 10.0.2 | |
IBM Security Verify Governance, Identity Manager Software Stack | <=ISVG 10.0.2 | |
IBM Security Verify Governance, Identity Manager Virtual Appliance | <=ISVG 10.0.2 | |
IBM Security Verify Governance Identity Manager Container | <=ISVG 10.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-26555 has been assigned a high severity rating due to its potential for impersonation attacks during Bluetooth pairing.
To fix CVE-2020-26555, users should update their affected software or firmware to the latest version provided by their vendors.
CVE-2020-26555 affects various devices including certain versions of Bluetooth Core Specification and specific Intel wireless firmware.
CVE-2020-26555 can lead to impersonation attacks during the Bluetooth BR/EDR PIN Pairing procedure.
Currently, the best practice is to promptly apply security updates from manufacturers to mitigate the risk associated with CVE-2020-26555.