PT-2020-17391 · Samsung+1 · Samsung Galaxy S6 Edge+7
Published
2020-12-24
·
Updated
2020-12-31
·
CVE-2020-35693
CVSS v3.1
8.8
High
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Samsung phones and tablets running Android versions prior to 7.1.2
Samsung Galaxy Note 5 version not specified
Samsung Galaxy S6 Edge version not specified
Samsung Galaxy A3 version not specified
Samsung Tab A (2017) version not specified
Samsung J2 Pro (2018) version not specified
Samsung Galaxy Note 4 version not specified
Samsung Galaxy S5 version not specified
Description
An attacker-controlled Bluetooth Low Energy (BLE) device can pair silently with a vulnerable target device without any user interaction when the target device's Bluetooth is on and it is running an app that offers a connectable BLE advertisement. Examples of such apps include Bluetooth-based contact tracing apps. During the pairing process, personally identifiable information such as the Identity Address of the Bluetooth adapter and its associated Identity Resolving Key (IRK) are exchanged, which can be used for long-term tracking of the target device.
Recommendations
For Samsung phones and tablets running Android versions prior to 7.1.2, update to a version newer than 7.1.1 to mitigate the risk.
For Samsung Galaxy Note 5, update to a newer version to mitigate the risk.
For Samsung Galaxy S6 Edge, update to a newer version to mitigate the risk.
For Samsung Galaxy A3, update to a newer version to mitigate the risk.
For Samsung Tab A (2017), update to a newer version to mitigate the risk.
For Samsung J2 Pro (2018), update to a newer version to mitigate the risk.
For Samsung Galaxy Note 4, update to a newer version to mitigate the risk.
For Samsung Galaxy S5, update to a newer version to mitigate the risk.
As a temporary workaround, consider disabling Bluetooth when not in use to minimize the risk of exploitation.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Android
Samsung Galaxy S3
Samsung Galaxy Note 4
Samsung Galaxy Note 5
Samsung Galaxy S5
Samsung Galaxy S6 Edge
Samsung J2 Pro
Samsung Tab A