PT-2023-7239 · Bluetooth Special Interest+10 · Bluetooth Core Specification+10

Published

2023-01-20

·

Updated

2026-03-14

·

CVE-2023-24023

CVSS v3.1

6.8

Medium

VectorAV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Bluetooth Core Specification versions 4.2 through 5.4
Description The issue is related to a man-in-the-middle attack that forces a short key length, potentially leading to the discovery of the encryption key and live injection. This vulnerability affects Bluetooth devices with Secure Simple Pairing and Secure Connections pairing, allowing an attacker to impersonate a device and intercept communications between paired devices. The estimated number of potentially affected devices worldwide is in the billions, including smartphones, laptops, and other mobile devices. The vulnerability is tracked under the identifier and was responsibly disclosed in October 2022.
Recommendations For Bluetooth Core Specification versions 4.2 through 5.4, consider the following measures to reduce the risk of similar threats:
  • Activate the key derivation function (KDF) for legacy secure connections (LSC)
  • Use a shared pairing key for mutual authentication of key diversifiers
  • Use secure connections (SC) mode where possible
  • Support a cache of session key diversifiers to prevent reuse Ensure connections have a key level of at least seven octets, use security mode 4, level 4, and operate devices in pairing mode with 'only secure connections' enabled.

Fix

Inadequate Encryption Strength

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2024:2394
ALSA-2024:2950
ALSA-2024:3138
ASB-A-255601934
BDU:2023-08267
CESA-2024_2950
CESA-2024_3138
CVE-2023-24023
INFSA-2024_2394
INFSA-2024_2950
INFSA-2024_3138
OPENSUSE-SU-2024_2362-1
OPENSUSE-SU-2024_2372-1
OPENSUSE-SU-2024_2394-1
RHSA-2024:2394
RHSA-2024:2950
RHSA-2024:3138
RHSA-2024_2394
RHSA-2024_2950
RHSA-2024_3138
RLSA-2024:2950
RLSA-2024:3138
SUSE-SU-2024:2360-1
SUSE-SU-2024:2362-1
SUSE-SU-2024:2365-1
SUSE-SU-2024:2372-1
SUSE-SU-2024:2381-1
SUSE-SU-2024:2384-1
SUSE-SU-2024:2385-1
SUSE-SU-2024:2394-1
SUSE-SU-2024:2495-1
SUSE-SU-2024:2561-1
SUSE-SU-2024:2939-1
USN-6739-1
USN-6740-1
USN-6741-1
USN-6742-1
USN-6742-2

Affected Products

Almalinux
Astra Linux
Bluetooth Core Specification
Centos
Debian
Linuxmint
Red Hat
Rocky Linux
Suse
Ubuntu
Windows