Overview
Bluetooth Basic Rate / Enhanced Data Rate (BR/EDR) Core Configurations are used for low-power short-range communications. To establish an encrypted connection, two Bluetooth devices must pair with each other using a link key. It is possible for an unauthenticated, adjacent attacker to impersonate a previously paired/bonded device and successfully authenticate without knowing the link key. This could allow an attacker to gain full access to the paired device by performing a Bluetooth Impersonation Attack (BIAS).
Description
Bluetooth is a short-range wireless technology based off of a core specification that defines six different core configurations, including the Bluetooth Basic Rate / Enhanced Data Rate (BR/EDR) Core Configurations. Bluetooth BR/EDR is used for low-power short-range communications. To establish an encrypted connection, two Bluetooth devices must pair with each other using a link key. It is possible for an unauthenticated, adjacent attacker to spoof the address of a previously paired remote device to successfully complete the authentication procedure with some paired/bonded devices without knowing the link key.
The Bluetooth Impersonation Attack (BIAS) can be performed in two different ways, depending on which Secure Simple Pairing method (either Legacy Secure Connections or Secure Connections) was previously used to establish a connection between two devices. If the pairing procedure was completed using the Secure Connections method, the attacker could claim to be the previously paired remote device that no longer supports secure connections, thereby downgrading the authentication security. This would allow the attacker to proceed with the BIAS method against the legacy authentication unless the device they are attacking is in Secure Connections only mode. If the attacker can either downgrade authentication or is attacking a device that does not support Secure Connections, they can perform the attack using a similar method by initiating a master-slave role switch to place itself into the master role and become the authentication initiator. If successful, they complete the authentication with the remote device. If the remote device does not then mutually authenticate with the attacker in the master role, it will result in the authentication-complete notification on both devices, even though the attacker does not possess the link key.
The BIAS method is able to be performed for the following reasons: Bluetooth secure connection establishment is not encrypted and the selection of secure connections pairing method is not enforced for an already established pairing, Legacy Secure Connections secure connection establishment does not require mutual authentication, a Bluetooth device can perform a role switch any time after baseband paging, and devices who paired using Secure Connections can use Legacy Secure Connections during secure connection establishment.
Impact
An unauthenticated, adjacent attacker could impersonate a Bluetooth BR/EDR master or slave to pair with a previously paired remote device to successfully complete the authentication procedure without knowing the link key. The BIAS attack could be combined with the Key Negotiation of Bluetooth (KNOB) attack to "impersonate a Bluetooth device, complete authentication without possessing the link key, negotiate a session key with low entropy, establish a secure connection, and brute force the session key". An attacker could initiate a KNOB attack on encryption key strength without intervening in an ongoing pairing procedure through an injection attack. If the accompanying KNOB attack is successful, an attacker may gain full access as the remote paired device. If the KNOB attack is unsuccessful, the attacker will not be able to establish an encrypted link but may still appear authenticated to the host.
Solution
Bluetooth host and controller suppliers should refer to the Bluetooth SIG's statement for guidance on updating their products. Downstream vendors should refer to their suppliers for updates.
Acknowledgements
Thanks to Daniele Antonioli of Singapore University of Technology and Design, Nils Ole Tippenhauer of CISPA Helmholtz Center for Information Security, and Kasper Rasmussen of the University of Oxford for reporting this vulnerability.
This document was written by Madison Oliver.
Vendor Information
Apple Affected
CVE-2020-10135 | Affected |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Bluetooth SIG Affected
CVE-2020-10135 | Affected |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
References
- https://www.bluetooth.com/learn-about-bluetooth/bluetooth-technology/blueto
- oth-security/bias-vulnerability/
CERT Addendum
There are no additional comments at this time.
Broadcom Affected
CVE-2020-10135 | Affected |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Cypress Semiconductor Affected
CVE-2020-10135 | Affected |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Qualcomm Affected
CVE-2020-10135 | Affected |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Samsung Affected
CVE-2020-10135 | Affected |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Check Point Not Affected
Statement Date: April 10, 2020
CVE-2020-10135 | Not Affected |
Vendor Statement
Not vulnerable.
CERT Addendum
There are no additional comments at this time.
LANCOM Systems GmbH Not Affected
Statement Date: May 17, 2020
CVE-2020-10135 | Not Affected |
Vendor Statement
LANCOM Systems products are not vulnerable to these vulnerabilities.
CERT Addendum
There are no additional comments at this time.
Zyxel Not Affected
Statement Date: April 13, 2020
CVE-2020-10135 | Not Affected |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Intel Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
Intel's Bluetooth Controllers (part of Wi-Fi/Bluetooth products) are not affected.
CERT Addendum
While the researchers have listed Intel controllers as affected by this vulnerability in their original report, Intel has disagreed and claims to be unaffected. The researchers have observed a lack of mutual authentication when using legacy secure connection, but that mutual authentication could, in theory, be implemented either in the controller or the host. The Bluetooth SIG has concluded that this was always the responsibility of the host and the current spec errata that have been adopted is just clarifying this fact. The host operating systems are responsible for implementing the mitigation.
A10 Networks Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
ACCESS Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Actelis Networks Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Actiontec Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
ADTRAN Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Aerohive Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
AhnLab Inc Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
AirWatch Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Akamai Technologies Inc. Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Alcatel-Lucent Enterprise Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Allied Telesis Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Alpine Linux Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Amazon Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Android Open Source Project Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
ANTlabs Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Arch Linux Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Arista Networks Inc. Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
ARRIS Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Aruba Networks Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Aspera Inc. Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
ASUSTeK Computer Inc. Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Atheros Communications Inc Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
AT&T Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Avaya Inc. Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
AVM GmbH Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Barracuda Networks Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Belden Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Belkin Inc. Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Bell Canada Enterprises Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
BlackBerry Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Blackberry QNX Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
BlueCat Networks Inc. Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Blue Coat Systems Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Blunk Microsystems Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
BoringSSL Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Brocade Communication Systems Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Buffalo Technology Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Cambium Networks Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
CA Technologies Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Ceragon Networks Inc Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Cirpack Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Cisco Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
CMX Systems Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Comcast Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Contiki OS Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
CoreOS Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Cradlepoint Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Cricket Wireless Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
CZ.NIC Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Debian GNU/Linux Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Dell Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Dell EMC Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Dell SecureWorks Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
DesktopBSD Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Deutsche Telekom Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Devicescape Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Digi International Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
D-Link Systems Inc. Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
dnsmasq Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
DragonFly BSD Project Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
eCosCentric Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
eero Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
EfficientIP Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
ENEA Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Ericsson Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Espressif Systems Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
European Registry for Internet Domains Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Express Logic Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Extreme Networks Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
F5 Networks Inc. Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Fastly Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Fedora Project Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Force10 Networks Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Fortinet Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Foundry Brocade Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
FreeBSD Project Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
F-Secure Corporation Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Geexbox Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Gentoo Linux Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
GFI Software Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
GNU adns Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
GNU glibc Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Google Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Grandstream Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Green Hills Software Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
HardenedBSD Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
HCC Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Hewlett Packard Enterprise Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Hitachi Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Honeywell Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
HP Inc. Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
HTC Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Huawei Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
IBM Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
IBM Corporation (zseries) Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Illumos Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Infoblox Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
InfoExpress Inc. Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Inmarsat Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Internet Systems Consortium Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Internet Systems Consortium - DHCP Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
INTEROP Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
JH Software Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Joyent Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Juniper Networks Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Lancope Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Lantronix Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Lenovo Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
LG Electronics Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
LibreSSL Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Linksys Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
LITE-ON Technology Corporation Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
LiteSpeed Technologies Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
lwIP Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Lynx Software Technologies Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
m0n0wall Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Marvell Semiconductor Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
McAfee Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
MediaTek Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Medtronic Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Men & Mice Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Metaswitch Networks Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Microchip Technology Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Micro Focus Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Microsoft Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
MikroTik Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Miredo Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Mitel Networks Inc. Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Motorola Inc. Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Muonics Inc. Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
NEC Corporation Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
NetBSD Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
NetBurner Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Netgear Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
NETSCOUT Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
netsnmp Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
netsnmpj Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Nexenta Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
NIKSUN Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Nixu Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
NLnet Labs Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Nokia Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Nominum Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
OleumTech Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
OpenBSD Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
OpenConnect Ltd Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
OpenSSL Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Openwall GNU/*/Linux Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
OpenWRT Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Oracle Corporation Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Oryx Embedded Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Paessler Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Palo Alto Networks Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Peplink Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
pfSense Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Philips Electronics Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
PHPIDS Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
PowerDNS Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Proxim Inc. Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Pulse Secure Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
QLogic Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Quadros Systems Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Quagga Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Quantenna Communications Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Red Hat Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Riverbed Technologies Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Rocket RTOS (Inactive) Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Roku Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Ruckus Wireless Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
SafeNet Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Samsung Mobile Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Secure64 Software Corporation Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Sierra Wireless Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Silvair Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Slackware Linux Inc. Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
SMC Networks Inc. Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
SmoothWall Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Snort Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
SonicWall Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Sonos Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Sony Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Sophos Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Sourcefire Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
SUSE Linux Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Symantec Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Synology Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
TCPWave Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
TDS Telecom Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Technicolor Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Tenable Network Security Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
TippingPoint Technologies Inc. Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Tizen Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Toshiba Commerce Solutions Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
TP-LINK Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Treck Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
TrueOS Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Turbolinux Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Ubiquiti Networks Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Ubuntu Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Unisys Corporation Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Untangle Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Vertical Networks Inc. Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
VMware Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Wind River Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
WizNET Technology Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
wolfSSL Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Xiaomi Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
XigmaNAS Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Xilinx Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Zebra Technologies Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Zephyr Project Unknown
CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | 4.8 | AV:A/AC:L/Au:N/C:P/I:P/A:N |
Temporal | 4.8 | E:ND/RL:ND/RC:ND |
Environmental | 4.8 | CDP:ND/TD:ND/CR:ND/IR:ND/AR:ND |
References
- https://www.bluetooth.com/learn-about-bluetooth/bluetooth-technology/bluetooth-security/bias-vulnerability/
- https://francozappa.github.io/about-bias/
- https://github.com/francozappa/bias
- https://publications.cispa.saarland/3064/
- https://www.youtube.com/watch?v=fASGU7Og5_4
- https://knobattack.com/
- https://www.bluetooth.com/learn-about-bluetooth/bluetooth-technology/bluetooth-security/reporting-security/
Other Information
CVE IDs: | CVE-2020-10135 |
API URL: | VINCE JSON | CSAF |
Date Public: | 2020-05-18 |
Date First Published: | 2020-05-18 |
Date Last Updated: | 2021-02-10 20:15 UTC |
Document Revision: | 32 |