CVE-2020-11957
Summary
| CVE | CVE-2020-11957 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-06-09 19:15:00 UTC |
| Updated | 2020-06-22 13:42:00 UTC |
| Description | The Bluetooth Low Energy implementation in Cypress PSoC Creator BLE 4.2 component versions before 3.64 generates a random number (Pairing Random) with significantly less entropy than the specified 128 bits during BLE pairing. This is the case for both authenticated and unauthenticated pairing with both LE Secure Connections as well as LE Legacy Pairing. A predictable or brute-forceable random number allows an attacker (in radio range) to perform a MITM attack during BLE pairing. |
Risk And Classification
Problem Types: CWE-331
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Cypress | Psoc 4.2 Ble | All | All | All | All |
| Application | Cypress | Psoc 4.2 Ble | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.cypress.com/file/504466/download | CONFIRM | www.cypress.com | Product, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.