Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-11957

Опубликовано: 09 июн. 2020
Источник: nvd
CVSS3: 7.5
CVSS2: 5.4
EPSS Низкий

Описание

The Bluetooth Low Energy implementation in Cypress PSoC Creator BLE 4.2 component versions before 3.64 generates a random number (Pairing Random) with significantly less entropy than the specified 128 bits during BLE pairing. This is the case for both authenticated and unauthenticated pairing with both LE Secure Connections as well as LE Legacy Pairing. A predictable or brute-forceable random number allows an attacker (in radio range) to perform a MITM attack during BLE pairing.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:cypress:psoc_4.2_ble:*:*:*:*:*:*:*:*
Версия до 3.64 (исключая)

EPSS

Процентиль: 30%
0.0011
Низкий

7.5 High

CVSS3

5.4 Medium

CVSS2

Дефекты

CWE-331

Связанные уязвимости

CVSS3: 7.5
github
больше 3 лет назад

The Bluetooth Low Energy implementation in Cypress PSoC Creator BLE 4.2 component versions before 3.64 generates a random number (Pairing Random) with significantly less entropy than the specified 128 bits during BLE pairing. This is the case for both authenticated and unauthenticated pairing with both LE Secure Connections as well as LE Legacy Pairing. A predictable or brute-forceable random number allows an attacker (in radio range) to perform a MITM attack during BLE pairing.

EPSS

Процентиль: 30%
0.0011
Низкий

7.5 High

CVSS3

5.4 Medium

CVSS2

Дефекты

CWE-331