1 results (0.001 seconds)

CVSS: 6.5EPSS: 0%CPEs: 2EXPL: 0

Nordic Semiconductor Android BLE Library through 2.2.1 and DFU Library through 1.10.4 for Android (as used by nRF Connect and other applications) can engage in unencrypted communication while showing the user that the communication is purportedly encrypted. The problem is in bond creation (e.g., internalCreateBond in BleManagerHandler). Nordic Semiconductor Android BLE Library versiones hasta 2.2.1 y DFU Library versiones hasta 1.10.4 para Android (tal como es usado nRF Connect y otras aplicaciones) puede participar en una comunicación no cifrada mientras le muestra al usuario que la comunicación está supuestamente cifrada. El problema está en la creación de enlaces (por ejemplo, internalCreateBond en BleManagerHandler) • https://github.com/NordicSemiconductor/Android-BLE-Library/commits/master https://github.com/NordicSemiconductor/Android-DFU-Library/commits/release https://secretdiary.ninja/index.php/2020/07/03/norec-attack-stripping-ble-encryption-from-nordicsemis-android-library-cve-2020-15509 • CWE-319: Cleartext Transmission of Sensitive Information •