PT-2020-12949 · Cypress · Cypress Psoc Creator Ble
Published
2020-06-09
·
Updated
2020-06-22
·
CVE-2020-11957
CVSS v3.1
7.5
High
| Vector | AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Cypress PSoC Creator BLE 4.2 component versions prior to 3.64
Description
The Bluetooth Low Energy implementation generates a random number with significantly less entropy than specified during BLE pairing, allowing an attacker in radio range to perform a man-in-the-middle (MITM) attack. This issue affects both authenticated and unauthenticated pairing with LE Secure Connections and LE Legacy Pairing.
Recommendations
For versions prior to 3.64, update to version 3.64 or later to resolve the issue. As a temporary workaround, consider restricting BLE pairing to trusted devices and environments to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cypress Psoc Creator Ble