CVE-2020-15509
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Nordic Semiconductor Android BLE Library through 2.2.1 and DFU Library through 1.10.4 for Android (as used by nRF Connect and other applications) can engage in unencrypted communication while showing the user that the communication is purportedly encrypted. The problem is in bond creation (e.g., internalCreateBond in BleManagerHandler).
Nordic Semiconductor Android BLE Library versiones hasta 2.2.1 y DFU Library versiones hasta 1.10.4 para Android (tal como es usado nRF Connect y otras aplicaciones) puede participar en una comunicación no cifrada mientras le muestra al usuario que la comunicación está supuestamente cifrada. El problema está en la creación de enlaces (por ejemplo, internalCreateBond en BleManagerHandler)
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-07-02 CVE Reserved
- 2020-07-07 CVE Published
- 2024-05-11 EPSS Updated
- 2024-08-04 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-319: Cleartext Transmission of Sensitive Information
CAPEC
References (3)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Nordicsemi Search vendor "Nordicsemi" | Android Ble Library Search vendor "Nordicsemi" for product "Android Ble Library" | <= 2.2.1 Search vendor "Nordicsemi" for product "Android Ble Library" and version " <= 2.2.1" | - |
Affected
| ||||||
Nordicsemi Search vendor "Nordicsemi" | Dfu Library Search vendor "Nordicsemi" for product "Dfu Library" | <= 1.10.4 Search vendor "Nordicsemi" for product "Dfu Library" and version " <= 1.10.4" | - |
Affected
|