PT-2020-17391 · Samsung+1 · Samsung Galaxy S6 Edge+7

Published

2020-12-24

·

Updated

2020-12-31

·

CVE-2020-35693

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Samsung phones and tablets running Android versions prior to 7.1.2 Samsung Galaxy Note 5 version not specified Samsung Galaxy S6 Edge version not specified Samsung Galaxy A3 version not specified Samsung Tab A (2017) version not specified Samsung J2 Pro (2018) version not specified Samsung Galaxy Note 4 version not specified Samsung Galaxy S5 version not specified
Description An attacker-controlled Bluetooth Low Energy (BLE) device can pair silently with a vulnerable target device without any user interaction when the target device's Bluetooth is on and it is running an app that offers a connectable BLE advertisement. Examples of such apps include Bluetooth-based contact tracing apps. During the pairing process, personally identifiable information such as the Identity Address of the Bluetooth adapter and its associated Identity Resolving Key (IRK) are exchanged, which can be used for long-term tracking of the target device.
Recommendations For Samsung phones and tablets running Android versions prior to 7.1.2, update to a version newer than 7.1.1 to mitigate the risk. For Samsung Galaxy Note 5, update to a newer version to mitigate the risk. For Samsung Galaxy S6 Edge, update to a newer version to mitigate the risk. For Samsung Galaxy A3, update to a newer version to mitigate the risk. For Samsung Tab A (2017), update to a newer version to mitigate the risk. For Samsung J2 Pro (2018), update to a newer version to mitigate the risk. For Samsung Galaxy Note 4, update to a newer version to mitigate the risk. For Samsung Galaxy S5, update to a newer version to mitigate the risk. As a temporary workaround, consider disabling Bluetooth when not in use to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2020-35693

Affected Products

Android
Samsung Galaxy S3
Samsung Galaxy Note 4
Samsung Galaxy Note 5
Samsung Galaxy S5
Samsung Galaxy S6 Edge
Samsung J2 Pro
Samsung Tab A