CVE-2022-25836 Details
Description
Bluetooth® Low Energy Pairing in Bluetooth Core Specification v4.0 through v5.3 may permit an unauthenticated MITM to acquire credentials with two pairing devices via adjacent access when the MITM negotiates Legacy Passkey Pairing with the pairing Initiator and Secure Connections Passkey Pairing with the pairing Responder and brute forces the Passkey entered by the user into the Initiator. The MITM attacker can use the identified Passkey value to complete authentication with the Responder via Bluetooth pairing method confusion.
A vulnerability exists in Bluetooth Low Energy (LE) pairing within Bluetooth Core Specification versions 4.0 through 5.3. This issue may allow an unauthenticated man-in-the-middle (MITM) attacker to intercept and acquire credentials from two pairing devices. The vulnerability arises when the MITM negotiates different pairing methods with the devices: Legacy Passkey Pairing with the Initiator and Secure Connections Passkey Pairing with the Responder. By brute-forcing the Passkey entered by the user into the Initiator, the MITM can use the identified Passkey to complete the authentication process with the Responder, exploiting the confusion between the two pairing methods.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 22, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-294 | Authentication Bypass by Capture-replay | [email protected] |
| CWE-294 | Authentication Bypass by Capture-replay | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| bluetooth bluetooth core specification | >= 4.0, <= 5.3 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 22, 2025 | CVE Modified | CISA-ADP |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Dec 14, 2022 | Initial Analysis | [email protected] |