Описание
Nordic Semiconductor Android BLE Library through 2.2.1 and DFU Library through 1.10.4 for Android (as used by nRF Connect and other applications) can engage in unencrypted communication while showing the user that the communication is purportedly encrypted. The problem is in bond creation (e.g., internalCreateBond in BleManagerHandler).
Ссылки
- PatchThird Party Advisory
- PatchThird Party Advisory
- PatchThird Party Advisory
- PatchThird Party Advisory
- PatchThird Party Advisory
- PatchThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2.2.1 (включая)Версия до 1.10.4 (включая)
Одно из
cpe:2.3:a:nordicsemi:android_ble_library:*:*:*:*:*:*:*:*
cpe:2.3:a:nordicsemi:dfu_library:*:*:*:*:*:*:*:*
EPSS
Процентиль: 16%
0.00051
Низкий
6.5 Medium
CVSS3
3.3 Low
CVSS2
Дефекты
CWE-319
Связанные уязвимости
CVSS3: 6.5
github
больше 3 лет назад
Nordic Semiconductor Android BLE Library through 2.2.1 and DFU Library through 1.10.4 for Android (as used by nRF Connect and other applications) can engage in unencrypted communication while showing the user that the communication is purportedly encrypted. The problem is in bond creation (e.g., internalCreateBond in BleManagerHandler).
EPSS
Процентиль: 16%
0.00051
Низкий
6.5 Medium
CVSS3
3.3 Low
CVSS2
Дефекты
CWE-319