PT-2020-12949 · Cypress · Cypress Psoc Creator Ble

Published

2020-06-09

·

Updated

2020-06-22

·

CVE-2020-11957

CVSS v3.1

7.5

High

VectorAV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cypress PSoC Creator BLE 4.2 component versions prior to 3.64
Description The Bluetooth Low Energy implementation generates a random number with significantly less entropy than specified during BLE pairing, allowing an attacker in radio range to perform a man-in-the-middle (MITM) attack. This issue affects both authenticated and unauthenticated pairing with LE Secure Connections and LE Legacy Pairing.
Recommendations For versions prior to 3.64, update to version 3.64 or later to resolve the issue. As a temporary workaround, consider restricting BLE pairing to trusted devices and environments to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-11957

Affected Products

Cypress Psoc Creator Ble