CVE-2020-35473
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
An information leakage vulnerability in the Bluetooth Low Energy advertisement scan response in Bluetooth Core Specifications 4.0 through 5.2, and extended scan response in Bluetooth Core Specifications 5.0 through 5.2, may be used to identify devices using Resolvable Private Addressing (RPA) by their response or non-response to specific scan requests from remote addresses. RPAs that have been associated with a specific remote device may also be used to identify a peer in the same manner by using its reaction to an active scan request. This has also been called an allowlist-based side channel.
Se puede utilizar una vulnerabilidad de fuga de información en la respuesta de escaneo de publicidad de Bluetooth Low Energy en las Especificaciones principales de Bluetooth 4.0 a 5.2, y la respuesta de escaneo extendida en las Especificaciones principales de Bluetooth 5.0 a 5.2, para identificar dispositivos que usan Resolvable Private Addressing (RPA) por su respuesta o no-respuesta a solicitudes de escaneo específicas desde direcciones remotas. Los RPA que se han asociado con un dispositivo remoto específico también se pueden usar para identificar a un par de la misma manera mediante su reacción a una solicitud de escaneo activo. A esto también se le ha denominado canal lateral basado en listas permitidas.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-12-16 CVE Reserved
- 2022-11-08 CVE Published
- 2024-05-31 EPSS Updated
- 2024-08-04 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-203: Observable Discrepancy
- CWE-294: Authentication Bypass by Capture-replay
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://dl.acm.org/doi/10.1145/3548606.3559372 | Technical Description | |
https://www.sigsac.org/ccs/CCS2022/proceedings/ccs-proceedings.html | Technical Description |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Bluetooth Search vendor "Bluetooth" | Bluetooth Core Specification Search vendor "Bluetooth" for product "Bluetooth Core Specification" | >= 4.0 <= 5.2 Search vendor "Bluetooth" for product "Bluetooth Core Specification" and version " >= 4.0 <= 5.2" | - |
Affected
|