Overview
Bluetooth Basic Rate / Enhanced Data Rate (BR/EDR) Core Configurations are used for low-power short-range communications. To establish an encrypted connection, two Bluetooth devices must pair with each other using a link key. It is possible for an unauthenticated, adjacent attacker to impersonate a previously paired/bonded device and successfully authenticate without knowing the link key. This could allow an attacker to gain full access to the paired device by performing a Bluetooth Impersonation Attack (BIAS).
Description
Bluetooth is a short-range wireless technology based off of a core specification that defines six different core configurations, including the Bluetooth Basic Rate / Enhanced Data Rate (BR/EDR) Core Configurations. Bluetooth BR/EDR is used for low-power short-range communications. To establish an encrypted connection, two Bluetooth devices must pair with each other using a link key. It is possible for an unauthenticated, adjacent attacker to spoof the address of a previously paired remote device to successfully complete the authentication procedure with some paired/bonded devices without knowing the link key.
The Bluetooth Impersonation Attack (BIAS) can be performed in two different ways, depending on which Secure Simple Pairing method (either Legacy Secure Connections or Secure Connections) was previously used to establish a connection between two devices. If the pairing procedure was completed using the Secure Connections method, the attacker could claim to be the previously paired remote device that no longer supports secure connections, thereby downgrading the authentication security. This would allow the attacker to proceed with the BIAS method against the legacy authentication unless the device they are attacking is in Secure Connections only mode. If the attacker can either downgrade authentication or is attacking a device that does not support Secure Connections, they can perform the attack using a similar method by initiating a master-slave role switch to place itself into the master role and become the authentication initiator. If successful, they complete the authentication with the remote device. If the remote device does not then mutually authenticate with the attacker in the master role, it will result in the authentication-complete notification on both devices, even though the attacker does not possess the link key.
The BIAS method is able to be performed for the following reasons: Bluetooth secure connection establishment is not encrypted and the selection of secure connections pairing method is not enforced for an already established pairing, Legacy Secure Connections secure connection establishment does not require mutual authentication, a Bluetooth device can perform a role switch any time after baseband paging, and devices who paired using Secure Connections can use Legacy Secure Connections during secure connection establishment.
Impact
An unauthenticated, adjacent attacker could impersonate a Bluetooth BR/EDR master or slave to pair with a previously paired remote device to successfully complete the authentication procedure without knowing the link key. The BIAS attack could be combined with the Key Negotiation of Bluetooth (KNOB) attack to "impersonate a Bluetooth device, complete authentication without possessing the link key, negotiate a session key with low entropy, establish a secure connection, and brute force the session key". An attacker could initiate a KNOB attack on encryption key strength without intervening in an ongoing pairing procedure through an injection attack. If the accompanying KNOB attack is successful, an attacker may gain full access as the remote paired device. If the KNOB attack is unsuccessful, the attacker will not be able to establish an encrypted link but may still appear authenticated to the host.
Solution
Bluetooth host and controller suppliers should refer to the Bluetooth SIG's statement for guidance on updating their products. Downstream vendors should refer to their suppliers for updates.
Acknowledgements
Thanks to Daniele Antonioli of Singapore University of Technology and Design, Nils Ole Tippenhauer of CISPA Helmholtz Center for Information Security, and Kasper Rasmussen of the University of Oxford for reporting this vulnerability.
This document was written by Madison Oliver.
Vendor Information
Apple Affected
| CVE-2020-10135 | Affected |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Bluetooth SIG Affected
| CVE-2020-10135 | Affected |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
References
- https://www.bluetooth.com/learn-about-bluetooth/bluetooth-technology/blueto
- oth-security/bias-vulnerability/
CERT Addendum
There are no additional comments at this time.
Broadcom Affected
| CVE-2020-10135 | Affected |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Cypress Semiconductor Affected
| CVE-2020-10135 | Affected |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Qualcomm Affected
| CVE-2020-10135 | Affected |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Samsung Affected
| CVE-2020-10135 | Affected |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Check Point Not Affected
Statement Date: April 10, 2020
| CVE-2020-10135 | Not Affected |
Vendor Statement
Not vulnerable.
CERT Addendum
There are no additional comments at this time.
LANCOM Systems GmbH Not Affected
Statement Date: May 17, 2020
| CVE-2020-10135 | Not Affected |
Vendor Statement
LANCOM Systems products are not vulnerable to these vulnerabilities.
CERT Addendum
There are no additional comments at this time.
Zyxel Not Affected
Statement Date: April 13, 2020
| CVE-2020-10135 | Not Affected |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Intel Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
Intel's Bluetooth Controllers (part of Wi-Fi/Bluetooth products) are not affected.
CERT Addendum
While the researchers have listed Intel controllers as affected by this vulnerability in their original report, Intel has disagreed and claims to be unaffected. The researchers have observed a lack of mutual authentication when using legacy secure connection, but that mutual authentication could, in theory, be implemented either in the controller or the host. The Bluetooth SIG has concluded that this was always the responsibility of the host and the current spec errata that have been adopted is just clarifying this fact. The host operating systems are responsible for implementing the mitigation.
A10 Networks Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
ACCESS Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Actelis Networks Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Actiontec Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
ADTRAN Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Aerohive Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
AhnLab Inc Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
AirWatch Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Akamai Technologies Inc. Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Alcatel-Lucent Enterprise Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Allied Telesis Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Alpine Linux Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Amazon Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Android Open Source Project Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
ANTlabs Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Arch Linux Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Arista Networks Inc. Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
ARRIS Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Aruba Networks Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Aspera Inc. Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
ASUSTeK Computer Inc. Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Atheros Communications Inc Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
AT&T Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Avaya Inc. Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
AVM GmbH Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Barracuda Networks Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Belden Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Belkin Inc. Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Bell Canada Enterprises Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
BlackBerry Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Blackberry QNX Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
BlueCat Networks Inc. Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Blue Coat Systems Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Blunk Microsystems Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
BoringSSL Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Brocade Communication Systems Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Buffalo Technology Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Cambium Networks Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
CA Technologies Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Ceragon Networks Inc Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Cirpack Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Cisco Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
CMX Systems Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Comcast Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Contiki OS Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
CoreOS Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Cradlepoint Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Cricket Wireless Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
CZ.NIC Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Debian GNU/Linux Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Dell Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Dell EMC Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Dell SecureWorks Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
DesktopBSD Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Deutsche Telekom Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Devicescape Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Digi International Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
D-Link Systems Inc. Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
dnsmasq Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
DragonFly BSD Project Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
eCosCentric Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
eero Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
EfficientIP Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
ENEA Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Ericsson Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Espressif Systems Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
European Registry for Internet Domains Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Express Logic Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Extreme Networks Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
F5 Networks Inc. Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Fastly Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Fedora Project Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Force10 Networks Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Fortinet Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Foundry Brocade Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
FreeBSD Project Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
F-Secure Corporation Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Geexbox Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Gentoo Linux Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
GFI Software Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
GNU adns Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
GNU glibc Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Google Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Grandstream Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Green Hills Software Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
HardenedBSD Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
HCC Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Hewlett Packard Enterprise Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Hitachi Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Honeywell Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
HP Inc. Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
HTC Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Huawei Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
IBM Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
IBM Corporation (zseries) Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Illumos Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Infoblox Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
InfoExpress Inc. Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Inmarsat Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Internet Systems Consortium Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Internet Systems Consortium - DHCP Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
INTEROP Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
JH Software Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Joyent Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Juniper Networks Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Lancope Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Lantronix Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Lenovo Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
LG Electronics Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
LibreSSL Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Linksys Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
LITE-ON Technology Corporation Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
LiteSpeed Technologies Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
lwIP Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Lynx Software Technologies Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
m0n0wall Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Marvell Semiconductor Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
McAfee Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
MediaTek Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Medtronic Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Men & Mice Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Metaswitch Networks Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Microchip Technology Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Micro Focus Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Microsoft Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
MikroTik Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Miredo Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Mitel Networks Inc. Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Motorola Inc. Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Muonics Inc. Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
NEC Corporation Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
NetBSD Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
NetBurner Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Netgear Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
NETSCOUT Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
netsnmp Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
netsnmpj Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Nexenta Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
NIKSUN Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Nixu Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
NLnet Labs Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Nokia Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Nominum Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
OleumTech Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
OpenBSD Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
OpenConnect Ltd Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
OpenSSL Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Openwall GNU/*/Linux Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
OpenWRT Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Oracle Corporation Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Oryx Embedded Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Paessler Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Palo Alto Networks Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Peplink Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
pfSense Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Philips Electronics Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
PHPIDS Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
PowerDNS Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Proxim Inc. Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Pulse Secure Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
QLogic Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Quadros Systems Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Quagga Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Quantenna Communications Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Red Hat Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Riverbed Technologies Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Rocket RTOS (Inactive) Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Roku Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Ruckus Wireless Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
SafeNet Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Samsung Mobile Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Secure64 Software Corporation Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Sierra Wireless Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Silvair Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Slackware Linux Inc. Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
SMC Networks Inc. Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
SmoothWall Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Snort Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
SonicWall Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Sonos Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Sony Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Sophos Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Sourcefire Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
SUSE Linux Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Symantec Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Synology Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
TCPWave Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
TDS Telecom Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Technicolor Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Tenable Network Security Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
TippingPoint Technologies Inc. Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Tizen Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Toshiba Commerce Solutions Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
TP-LINK Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Treck Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
TrueOS Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Turbolinux Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Ubiquiti Networks Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Ubuntu Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Unisys Corporation Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Untangle Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Vertical Networks Inc. Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
VMware Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Wind River Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
WizNET Technology Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
wolfSSL Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Xiaomi Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
XigmaNAS Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Xilinx Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Zebra Technologies Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
Zephyr Project Unknown
| CVE-2020-10135 | Unknown |
Vendor Statement
No statement is currently available from the vendor regarding this vulnerability.
CERT Addendum
There are no additional comments at this time.
CVSS Metrics
| Group | Score | Vector |
|---|---|---|
| Base | 4.8 | AV:A/AC:L/Au:N/C:P/I:P/A:N |
| Temporal | 4.8 | E:ND/RL:ND/RC:ND |
| Environmental | 4.8 | CDP:ND/TD:ND/CR:ND/IR:ND/AR:ND |
References
- https://www.bluetooth.com/learn-about-bluetooth/bluetooth-technology/bluetooth-security/bias-vulnerability/
- https://francozappa.github.io/about-bias/
- https://github.com/francozappa/bias
- https://publications.cispa.saarland/3064/
- https://www.youtube.com/watch?v=fASGU7Og5_4
- https://knobattack.com/
- https://www.bluetooth.com/learn-about-bluetooth/bluetooth-technology/bluetooth-security/reporting-security/
Other Information
| CVE IDs: | CVE-2020-10135 |
| API URL: | VINCE JSON | CSAF |
| Date Public: | 2020-05-18 |
| Date First Published: | 2020-05-18 |
| Date Last Updated: | 2021-02-10 20:15 UTC |
| Document Revision: | 32 |