Bluetooth SIG Bluetooth Protocol Device Pairing Process Vulnerability
BID:13854
Info
Bluetooth SIG Bluetooth Protocol Device Pairing Process Vulnerability
| Bugtraq ID: | 13854 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 03 2005 12:00AM |
| Updated: | Jun 03 2005 12:00AM |
| Credit: | Discovery of this issue is credited to Yaniv Shaked and Avishai Wool. |
| Vulnerable: |
Bluetooth SIG Bluetooth |
| Not Vulnerable: | |
Discussion
Bluetooth SIG Bluetooth Protocol Device Pairing Process Vulnerability
The BlueTooth protocol is prone to a vulnerability that exists in the device pairing process. The issue manifests due to a flaw in the device pairing process that allows a malicious third party device to force device pairing in order to determine a valid link key and in turn launch attacks designed to crack a target PIN (Personal Identification Number).
An attacker may force device re-pairing in order to derive sensitive information in regards to a target connection.
The BlueTooth protocol is prone to a vulnerability that exists in the device pairing process. The issue manifests due to a flaw in the device pairing process that allows a malicious third party device to force device pairing in order to determine a valid link key and in turn launch attacks designed to crack a target PIN (Personal Identification Number).
An attacker may force device re-pairing in order to derive sensitive information in regards to a target connection.
Exploit / POC
Bluetooth SIG Bluetooth Protocol Device Pairing Process Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Bluetooth SIG Bluetooth Protocol Device Pairing Process Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Bluetooth SIG Bluetooth Protocol Device Pairing Process Vulnerability
References:
References:
- Cracking the Bluetooth PIN (Yaniv Shaked and Avishai Wool)
- Specification - Qualification and Testing (Bluetooth.org)