PT-2022-5920 · Linux+1 · Linux Kernel+1
Published
2022-12-11
·
Updated
2025-10-23
·
CVE-2022-25837
CVSS v3.1
7.5
High
| Vector | AV:A/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Bluetooth Core Specification versions 1.0B through 5.3
Linux kernel (affected versions not specified)
Description
The issue concerns Bluetooth pairing and may allow an unauthenticated Man-In-The-Middle (MITM) attacker to acquire credentials when two devices are paired, one supporting BR/EDR Secure Connections pairing and the other BR/EDR Legacy PIN code pairing. The MITM negotiates BR/EDR Secure Simple Pairing in Secure Connections mode with the pairing Initiator and BR/EDR Legacy PIN code pairing with the pairing Responder, then brute forces the Passkey entered by the user into the Responder as a 6-digit PIN code. The identified PIN code value can be used to complete authentication with the Initiator via Bluetooth pairing method confusion. Additionally, there is a vulnerability in the Linux kernel's Bluetooth driver related to authentication procedure errors, which may allow a remote attacker to elevate their privileges.
Recommendations
For Bluetooth Core Specification versions 1.0B through 5.3, consider disabling the BR/EDR Secure Simple Pairing in Secure Connections mode using the Passkey association model as a temporary workaround until a patch is available.
For Linux kernel, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bluetooth Core Specification
Linux Kernel