PT-2019-3023 · Bluetooth+6 · Bluetooth Br/Edr+6

Daniele Antonioli

+2

·

Published

2019-04-25

·

Updated

2021-11-04

·

CVE-2019-9506

CVSS v3.1

8.1

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Bluetooth BR/EDR versions up to and including 5.1
Description The issue concerns the Bluetooth BR/EDR specification, which permits sufficiently low encryption key length and does not prevent an attacker from influencing the key length negotiation. This allows practical brute-force attacks that can decrypt traffic and inject arbitrary ciphertext without the victim noticing. The vulnerability can be exploited by an unauthenticated, adjacent attacker to initiate a man-in-the-middle attack, reducing the negotiated entropy length used for secure connections. The flaw affects a wide range of Bluetooth-enabled devices, including smartphones, laptops, IoT devices, and industrial devices.
Recommendations For Bluetooth BR/EDR versions up to and including 5.1, consider disabling the key negotiation process until a patch is available. As a temporary workaround, restrict access to the encryption key negotiation process to minimize the risk of exploitation. Avoid using the Bluetooth BR/EDR protocol for sensitive connections until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use of a Broken Cryptographic Algorithm

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-03002
CESA-2019_3055
CESA-2019_3309
CESA-2019_3517
CVE-2019-9506
DLA-1919-1
DLA-1919-2
DLA-1930-1
OPENSUSE-SU-2019:2307-1
OPENSUSE-SU-2019:2308-1
OPENSUSE-SU-2019_2307-1
OPENSUSE-SU-2019_2308-1
RHSA-2019:2975
RHSA-2019:3055
RHSA-2019:3076
RHSA-2019:3089
RHSA-2019:3165
RHSA-2019:3187
RHSA-2019:3217
RHSA-2019:3218
RHSA-2019:3220
RHSA-2019:3231
RHSA-2019:3309
RHSA-2019:3517
RHSA-2019_3055
RHSA-2019_3089
RHSA-2019_3309
RHSA-2019_3517
RHSA-2020:0204
RHSA-2020:1460
SUSE-SU-2019:2648-1
SUSE-SU-2019:2651-1
SUSE-SU-2019:2658-1
SUSE-SU-2019:2706-1
SUSE-SU-2019:2710-1
SUSE-SU-2019:2756-1
SUSE-SU-2019:2879-1
SUSE-SU-2019:2949-1
SUSE-SU-2019:2950-1
SUSE-SU-2019:2984-1
SUSE-SU-2019:3200-1
SUSE-SU-2019:3295-1
SUSE-SU-2020:0093-1
USN-4115-1
USN-4115-2
USN-4118-1
USN-4147-1

Affected Products

Bluetooth Br/Edr
Centos
Huawei Vrp
Red Hat
Suse
Ubuntu
Windows