Bluetooth Bug Opens Devices to Man-in-the-Middle Attacks
#1
Information 
Quote:A high-severity Bluetooth vulnerability has been uncovered, which could enable an unauthenticated attacker within wireless range to eavesdrop or alter communications between paired devices.
 
The flaw (CVE-2020-15802), discovered independently by researchers at the École Polytechnique Fédérale de Lausanne (EPFL) and Purdue University, is being referred to as “BLURtooth.” The issue exists in the pairing process for Bluetooth 4.0 through 5.0 implementations. This pairing process is called Cross-Transport Key Derivation (CTKD).
 
“Devices… using [CTKD] for pairing are vulnerable to key overwrite, which enables an attacker to gain additional access to profiles or services that are not restricted, by reducing the encryption key strength or overwriting an authenticated key with an unauthenticated key,” according to a security advisory on Wednesday by the Carnegie Mellon CERT Coordination Center.

There are two types of Bluetooth protocols related to the attack – the older Bluetooth Classic (also known as Bluetooth Basic Rate/Enhanced Data Rate, or BR/EDR) and newer Bluetooth Low Energy (BLE). While BR/EDR are mainly used for audio applications such as wireless telephone connections, wireless headphones and wireless speakers, BLE is more often seen in wearable devices, smart IoT devices, fitness monitoring equipment and battery-powered accessories such as a keyboard.

Read more: https://threatpost.com/bluetooth-bug-mit...ks/159124/
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
AxCrypt 3.1.5.0
AxCrypt 3.1.5.0: ...harlan4096 — 11:50
AMD will reinstate memory encryption on ...
The feature was qu...harlan4096 — 11:48
Microsoft confirms Windows 11 version 26...
Who would have gue...harlan4096 — 11:46
Windows 11 June 2026 Update Breaks Recyc...
Microsoft has conf...harlan4096 — 11:45
Microsoft Edge 149.0.4022.80
Release Summary ...harlan4096 — 15:38

[-]
Birthdays
Today's Birthdays
avatar (48)kinotHeemn
avatar (39)Ceballos1976
Upcoming Birthdays
avatar (39)Tedscolo
avatar (46)brakasig
avatar (40)efynu

[-]
Online Staff
There are no staff members currently online.

>