CVE-2020-10135 PUBLISHED

Legacy pairing and secure-connections pairing authentication in Bluetooth BR/EDR Core Specification v5.2 and earlier may allow an unauthenticated user to complete authentication without pairing credentials via adjacent access. An unauthenticated, adjacent attacker could impersonate a Bluetooth BR/EDR master or slave to pair with a previously paired remote device to successfully complete the authentication procedure without knowing the link key.

EPSS 20.19% · 95.4th percentile

Risk Scores

EPSS Score
20.19%
95.4th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:20.04:LTSlinux-azure-fde-5.155.15.0-1043.50~20.04.1.1, 5.15.0-1033.40~20.04.1.1, 5.15.0-1034.41~20.04.1.2
Ubuntu:Pro:FIPS-updates:18.04:LTSlinux-azure-fips4.15.0-2015.17, 4.15.0-2012.14, 4.15.0-2013.15
Ubuntu:24.04:LTSlinux-raspi-realtime0, 6.8.0-2019.20
Ubuntu:16.04:LTSlinux4.4.0-18.34, 4.4.0-194.226, 4.4.0-193.224
Ubuntu:Pro:14.04:LTSlinux-azure4.15.0-1059.64~14.04.1, 4.15.0-1056.61~14.04.1, 4.15.0-1055.60~14.04.1
Ubuntu:18.04:LTSlinux-gcp-5.35.3.0-1032.34~18.04.1, 5.3.0-1030.32~18.04.1, 5.3.0-1029.31~18.04.1
Ubuntu:16.04:LTSlinux-hwe-edge0, 4.8.0-28.30~16.04.1, 4.8.0-30.32~16.04.1
Ubuntu:18.04:LTSlinux-aws-5.45.4.0-1024.24~18.04.1, 5.4.0-1022.22~18.04.1, 5.4.0-1020.20~18.04.2
Ubuntu:Pro:FIPS-updates:18.04:LTSlinux-fips4.15.0-1029.34, 4.15.0-1027.32, 0
Ubuntu:18.04:LTSlinux-azure4.15.0-1035.36, 4.15.0-1032.33, 4.15.0-1031.32
Ubuntu:18.04:LTSlinux-raspi24.15.0-1017.18, 4.15.0-1020.22, 4.15.0-1021.23
Ubuntu:20.04:LTSlinux-kvm5.4.0-1018.18, 5.4.0-1020.20, 5.4.0-1021.21
Ubuntu:18.04:LTSlinux-oracle4.15.0-1015.17, 4.15.0-1061.67, 4.15.0-1059.65
Ubuntu:18.04:LTSlinux-gcp-5.40, 5.4.0-1029.31~18.04.1, 5.4.0-1028.29~18.04.1
Ubuntu:18.04:LTSlinux-aws-5.05.0.0-1022.25~18.04.1, 5.0.0-1023.26~18.04.1, 5.0.0-1024.27~18.04.1
Ubuntu:18.04:LTSlinux-hwe-5.45.4.0-40.44~18.04.1, 5.4.0-54.60~18.04.1, 5.4.0-53.59~18.04.1
Ubuntu:18.04:LTSlinux-gcp-edge4.18.0-1012.13~18.04.1, 4.18.0-1013.14~18.04.1, 4.18.0-1015.16~18.04.1
Ubuntu:18.04:LTSlinux-azure-edge0, 4.18.0-1007.7~18.04.1, 4.18.0-1008.8~18.04.1
Ubuntu:Pro:14.04:LTSlinux3.13.0-110.157, 3.13.0-109.156, 3.13.0-108.155
Ubuntu:18.04:LTSlinux-oem0, 4.15.0-1002.3, 4.15.0-1004.5

…and 55 more

Timeline

References

Open in Interactive Console →