CVE-2020-15802 PUBLISHED

Devices supporting Bluetooth before 5.1 may allow man-in-the-middle attacks, aka BLURtooth. Cross Transport Key Derivation in Bluetooth Core Specification v4.2 and v5.0 may permit an unauthenticated user to establish a bonding with one transport, either LE or BR/EDR, and replace a bonding already established on the opposing transport, BR/EDR or LE, potentially overwriting an authenticated key with an unauthenticated key, or a key with greater entropy with one with less.

EPSS 55.49% · 98.0th percentile

Risk Scores

EPSS Score
55.49%
98.0th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:16.04:LTSlinux-hwe4.15.0-38.41~16.04.1, 4.15.0-39.42~16.04.1, 4.15.0-42.45~16.04.1
Ubuntu:Pro:16.04:LTSlinux-oracle*, *, *
Ubuntu:Pro:20.04:LTSlinux-iot5.4.0-1028.29, 5.4.0-1025.26, 5.4.0-1022.23
Ubuntu:22.04:LTSlinux-ibm5.15.0-1023.26, 5.15.0-1025.28, 5.15.0-1022.25
Ubuntu:Pro:20.04:LTSlinux-ibm-5.155.15.0-1095.98~20.04.1, 5.15.0-1093.96~20.04.1, 5.15.0-1091.94~20.04.1
Ubuntu:22.04:LTSlinux-oem-6.06.0.0-1012.12, 6.0.0-1021.21, 6.0.0-1013.13
Ubuntu:20.04:LTSlinux-gkeop-5.155.15.0-1013.17~20.04.1, *, *
Ubuntu:Pro:20.04:LTSlinux-ibm5.4.0-1044.49, 5.4.0-1042.47, 5.4.0-1037.42
Ubuntu:Pro:18.04:LTSlinux-hwe-5.4*, *, *
Ubuntu:Pro:FIPS-preview:22.04:LTSlinux-gcp-fips*, 0
Ubuntu:24.04:LTSlinux-gcp-6.116.11.0-1017.17~24.04.1, *, *
Ubuntu:22.04:LTSlinux-azure-6.26.2.0-1007.7~22.04.1, 6.2.0-1006.6~22.04.1, *
Ubuntu:Pro:FIPS-updates:20.04:LTSlinux-gcp-fips5.4.0-1125.134+fips1, *, 5.4.0-1078.84+fips1
Ubuntu:20.04:LTSlinux-azure-5.8*, 0, 5.8.0-1033.35~20.04.1
Ubuntu:22.04:LTSlinux-gke5.15.0-1036.41, 5.15.0-1034.39, 5.15.0-1059.64
Ubuntu:18.04:LTSlinux-hwe-edge0, 5.3.0-22.24~18.04.1, 5.3.0-23.25~18.04.1
Ubuntu:24.04:LTSlinux-oracle-6.146.14.0-1011.11~24.04.1, 6.14.0-1012.12~24.04.1, 6.14.0-1010.10~24.04.1
Ubuntu:22.04:LTSlinux-allwinner-5.195.19.0-1012.12~22.04.1, 5.19.0-1013.13~22.04.1, 5.19.0-1014.14~22.04.1
Ubuntu:Pro:20.04:LTSlinux-hwe-5.155.15.0-151.161~20.04.1, 5.15.0-145.158~20.04.1, 5.15.0-144.157~20.04.1
Ubuntu:24.04:LTSlinux-azure-nvidia6.8.0-1013.14, 0, 6.8.0-1014.15

…and 219 more

Timeline

References

Open in Interactive Console →