CVE-2020-10135 Details
Description
Legacy pairing and secure-connections pairing authentication in Bluetooth BR/EDR Core Specification v5.2 and earlier may allow an unauthenticated user to complete authentication without pairing credentials via adjacent access. An unauthenticated, adjacent attacker could impersonate a Bluetooth BR/EDR master or slave to pair with a previously paired remote device to successfully complete the authentication procedure without knowing the link key.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-290 | Authentication Bypass by Spoofing | [email protected] |
| CWE-757 | Selection of Less-Secure Algorithm During Negotiation ('Algorithm Downgrade') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| bluetooth bluetooth core | <= 5.2 |
CPE
Remediation
| |
| opensuse leap | 15.1 |
CPE
Remediation
| |
Change History
11 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Dec 21, 2021 | Modified Analysis | [email protected] |
| Nov 2, 2020 | CVE Modified | [email protected] |
| Aug 21, 2020 | CVE Modified | [email protected] |
| Aug 14, 2020 | Modified Analysis | [email protected] |
| Aug 6, 2020 | CVE Modified | [email protected] |
| Jun 3, 2020 | CVE Modified | [email protected] |
| Jun 3, 2020 | CVE Modified | [email protected] |
| May 21, 2020 | Initial Analysis | [email protected] |