Vulnerability

CVE-2020-26555

Component: BLUETOOTH
Bluetooth legacy BR/EDR PIN code pairing in Bluetooth Core Specification 1.0B through 5.2 may permit an unauthenticated nearby device to spoof the BD_ADDR of the peer device to complete pairing without knowledge of the PIN.

Impact

Severity (Manufact.)

HIGH

Severity (NIST)

5.4

Severity (Android)

N/A

Chipsets

17

Devices

650

Affected Hardware

NameAlso known asManufacturer
MSM8208
Snapdragon 208
Qualcomm
MSM8917
Snapdragon 425
Qualcomm
MSM8920
Snapdragon 427
Qualcomm
MSM8937
Snapdragon 430
Qualcomm
MSM8940
Snapdragon 435
Qualcomm
MSM8953
Snapdragon 625
Qualcomm
SDM630
Snapdragon 630
Qualcomm
SDM636
Snapdragon 636
Qualcomm
SM6150
Snapdragon 675
Qualcomm
MSM8992
Snapdragon 808
Qualcomm
17 of 17 row(s) shown.

Rows per page

Page 1 of 2

Timeline

Introduced (est):
Jan 1, 2014
Reported:
Sep 7, 2020
Advisory Published:
Jun 7, 2021
CVE Published:
May 24, 2021
Android Patch Level:
Jun 2021
For more information and a detailed analysis of the data presented on this website, please see our paper, to be presented at NDSS'25.
Follow us on Twitter