CVE-2020-26555

Bluetooth legacy BR/EDR PIN code pairing in Bluetooth Core Specification 1.0B through 5.2 may permit an unauthenticated nearby device to spoof the BD_ADDR of the peer device to complete pairing without knowledge of the PIN.
Configurations

Configuration 1 (hide)

cpe:2.3:a:bluetooth:bluetooth_core_specification:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:intel:ax210_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:intel:ax210:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:intel:ax201_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:intel:ax201:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:intel:ax200_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:intel:ax200:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:intel:ac_9560_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:intel:ac_9560:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:intel:ac_9462_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:intel:ac_9462:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:intel:ac_9461_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:intel:ac_9461:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:intel:ac_9260_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:intel:ac_9260:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:intel:ac_8265_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:intel:ac_8265:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:intel:ac_8260_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:intel:ac_8260:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
cpe:2.3:o:intel:ac_3168_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:intel:ac_3168:-:*:*:*:*:*:*:*

Configuration 13 (hide)

AND
cpe:2.3:o:intel:ac_7265_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:intel:ac_7265:-:*:*:*:*:*:*:*

Configuration 14 (hide)

AND
cpe:2.3:o:intel:ac_3165_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:intel:ac_3165:-:*:*:*:*:*:*:*

Configuration 15 (hide)

AND
cpe:2.3:o:intel:killer_wi-fi_6e_ax1675_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:intel:killer_wi-fi_6e_ax1675:-:*:*:*:*:*:*:*

Configuration 16 (hide)

AND
cpe:2.3:o:intel:killer_wi-fi_6_ax1650_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:intel:killer_wi-fi_6_ax1650:-:*:*:*:*:*:*:*

Configuration 17 (hide)

AND
cpe:2.3:o:intel:killer_ac_1550_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:intel:killer_ac_1550:-:*:*:*:*:*:*:*

History

08 Jun 2021, 18:15

Type Values Removed Values Added
References
  • (CONFIRM) https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00520.html -

02 Jun 2021, 15:20

Type Values Removed Values Added
CPE cpe:2.3:a:bluetooth:bluetooth_core_specification:*:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : 4.8
v3 : 5.4
CWE CWE-863
References (MISC) https://www.bluetooth.com/learn-about-bluetooth/key-attributes/bluetooth-security/reporting-security/ - (MISC) https://www.bluetooth.com/learn-about-bluetooth/key-attributes/bluetooth-security/reporting-security/ - Vendor Advisory
References (MISC) https://kb.cert.org/vuls/id/799380 - (MISC) https://kb.cert.org/vuls/id/799380 - Third Party Advisory, US Government Resource
References (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NSS6CTGE4UGTJLCOZOASDR3T3SLL6QJZ/ - (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NSS6CTGE4UGTJLCOZOASDR3T3SLL6QJZ/ - Mailing List, Third Party Advisory

28 May 2021, 03:15

Type Values Removed Values Added
References
  • (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NSS6CTGE4UGTJLCOZOASDR3T3SLL6QJZ/ -

24 May 2021, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2021-05-24 18:15

Updated : 2024-02-04 21:47


NVD link : CVE-2020-26555

Mitre link : CVE-2020-26555

CVE.ORG link : CVE-2020-26555


JSON object : View

Products Affected

intel

  • killer_wi-fi_6_ax1650
  • ac_7265_firmware
  • ac_9560_firmware
  • ac_9461_firmware
  • ac_9260_firmware
  • ax201_firmware
  • killer_ac_1550
  • ax201
  • ac_9560
  • killer_wi-fi_6e_ax1675
  • ax210
  • ac_7265
  • ac_9462_firmware
  • ac_3165_firmware
  • ax200
  • killer_ac_1550_firmware
  • ac_9462
  • killer_wi-fi_6e_ax1675_firmware
  • ac_9461
  • ac_9260
  • killer_wi-fi_6_ax1650_firmware
  • ac_8265
  • ac_8260
  • ac_3168
  • ax210_firmware
  • ac_3168_firmware
  • ac_3165
  • ax200_firmware
  • ac_8265_firmware
  • ac_8260_firmware

fedoraproject

  • fedora

bluetooth

  • bluetooth_core_specification
CWE
CWE-863

Incorrect Authorization