VDB
CVE-2020-15509
CVE-2020-15509
PUBLISHED
CVSS 6.5 MEDIUM
Nordic Semiconductor Android BLE Library through 2.2.1 and DFU Library through 1.10.4 for Android (as used by nRF Connect and other applications) can engage in unencrypted communication while showing the user that the communication is purportedly encrypted. The problem is in bond creation (e.g., internalCreateBond in BleManagerHandler).
EPSS 0.54% · 44.3th percentile
Risk Scores
CVSS 3.1
6.5
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
0.54%
44.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| nordicsemi | dfu_library | 0 |
| n/a | n/a | n/a |
| nordicsemi | android_ble_library | 0 |
Timeline
- Jul 7, 2020 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Aug 25, 2021 EPSS Score
- Oct 27, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Feb 4, 2022 EPSS Score
- Mar 1, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- May 3, 2022 EPSS Score
- Jul 5, 2022 EPSS Score
- Sep 7, 2022 EPSS Score
References
- https://github.com/NordicSemiconductor/Android-BLE-Library/commits/master url
- https://github.com/NordicSemiconductor/Android-DFU-Library/commits/release url
- https://secretdiary.ninja/index.php/2020/07/03/norec-attack-stripping-ble-encryption-from-nordicsemis-android-library-cve-2020-15509/ url
- https://nvd.nist.gov/vuln/detail/CVE-2020-15509 advisory
- https://secretdiary.ninja/index.php/2020/07/03/norec-attack-stripping-ble-encryption-from-nordicsemis-android-library-cve-2020-15509 url