PT-2020-5393 · Bluetooth+5 · Bluetooth Core Specification+5

Daniele Antonioli

+2

·

Published

2020-05-18

·

Updated

2025-12-08

·

CVE-2020-10135

CVSS v3.1

5.4

Medium

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Bluetooth BR/EDR Core Specification versions prior to v5.2
Description The issue concerns a flaw in the authentication procedure of the Bluetooth BR/EDR protocol, allowing an unauthenticated, adjacent attacker to impersonate a Bluetooth BR/EDR master or slave and pair with a previously paired remote device without knowing the link key. This could potentially compromise the confidentiality and integrity of protected information.
Recommendations For Bluetooth BR/EDR Core Specification versions prior to v5.2, consider implementing additional authentication measures or restricting access to sensitive data until a patch or update is available. As a temporary workaround, restrict the use of legacy pairing and secure-connections pairing authentication to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Authentication Bypass by Spoofing

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_12746
ALSA-2025_12752
ALSA-2025_12753
ALSA-2025_16880
ALSA-2025_18281
ALSA-2025_19102
ALSA-2025_19103
ALSA-2025_19409
ALSA-2025_19931
ALSA-2025_19932
ALSA-2025_22800
ALSA-2025_22801
BDU:2021-00474
CVE-2020-10135
ELSA-2024-9315
INFSA-2024_9315
OPENSUSE-SU-2020:1153-1
OPENSUSE-SU-2020:1236-1
OPENSUSE-SU-2020_1153-1
OPENSUSE-SU-2020_1236-1
OPENSUSE-SU-2021:0242-1
OPENSUSE-SU-2021_0242-1
OPENSUSE-SU-2024:10728-1
OPENSUSE-SU-2024:13704-1
RHSA-2024:9315
RHSA-2024_9315
SUSE-SU-2020:2102-1
SUSE-SU-2020:2105-1
SUSE-SU-2020:2119-1
SUSE-SU-2020:2122-1
SUSE-SU-2020:2134-1
SUSE-SU-2020:2152-1
SUSE-SU-2020:2487-1
SUSE-SU-2020:2541-1
SUSE-SU-2020:2575-1
SUSE-SU-2020:2605-1
SUSE-SU-2020:2610-1
SUSE-SU-2020:2623-1
SUSE-SU-2020_2102-1
SUSE-SU-2020_2105-1
SUSE-SU-2020_2119-1
SUSE-SU-2020_2122-1
SUSE-SU-2020_2134-1
SUSE-SU-2020_2152-1
SUSE-SU-2020_2487-1
SUSE-SU-2020_2541-1
SUSE-SU-2024:2360-1
SUSE-SU-2024:2365-1
SUSE-SU-2024:2561-1
SUSE-SU-2024_2360-1
SUSE-SU-2024_2365-1
SUSE-SU-2024_2561-1
USN-4657-1
USN-4658-1
USN-4658-2
USN-4659-1
USN-4680-1
USN-4752-1

Affected Products

Astra Linux
Bluetooth Core Specification
Linuxmint
Red Hat
Suse
Ubuntu