CVE-2021-37577 Details
Description
Bluetooth LE and BR/EDR Secure Connections pairing and Secure Simple Pairing using the Passkey entry protocol in Bluetooth Core Specifications 2.1 through 5.3 may permit an unauthenticated man-in-the-middle attacker to identify the Passkey used during pairing by reflection of a crafted public key with the same X coordinate as the offered public key and by reflection of the authentication evidence of the initiating device, potentially permitting this attacker to complete authenticated pairing with the responding device using the correct Passkey for the pairing session. This is a related issue to CVE-2020-26558.
A vulnerability exists in Bluetooth Low Energy (LE) and Basic Rate/Enhanced Data Rate (BR/EDR) Secure Connections pairing, as well as in Secure Simple Pairing using the Passkey entry protocol, across Bluetooth Core Specifications 2.1 to 5.3. This vulnerability may allow an unauthenticated man-in-the-middle attacker to intercept and identify the Passkey used during the pairing process. The attacker can achieve this by reflecting a crafted public key that matches the X coordinate of the original public key offered by the initiating device, along with the authentication evidence from that device. By doing so, the attacker could potentially complete the authenticated pairing process with the responding device using the correct Passkey, thereby exploiting the vulnerability.
Bluetooth devices should be updated to follow the recommendations in Bluetooth Core Specification 5.4, which advises rejecting public keys that have matching X coordinates, except in specific debugging scenarios. For devices that cannot be updated, it is recommended to disable pairing or bonding features.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Oct 1, 2024CISA-ADP
Assessed Oct 1, 2024References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-639 | Authorization Bypass Through User-Controlled Key | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| Bluetooth | >= 2.1, <= 5.4 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 15, 2024 | CVE Modified | CISA-ADP |
| Oct 1, 2024 | New CVE Received | [email protected] |
Volerion