Bluetooth Bug Opens Devices to Man-in-the-Middle Attacks
#1
Information 
Quote:A high-severity Bluetooth vulnerability has been uncovered, which could enable an unauthenticated attacker within wireless range to eavesdrop or alter communications between paired devices.
 
The flaw (CVE-2020-15802), discovered independently by researchers at the École Polytechnique Fédérale de Lausanne (EPFL) and Purdue University, is being referred to as “BLURtooth.” The issue exists in the pairing process for Bluetooth 4.0 through 5.0 implementations. This pairing process is called Cross-Transport Key Derivation (CTKD).
 
“Devices… using [CTKD] for pairing are vulnerable to key overwrite, which enables an attacker to gain additional access to profiles or services that are not restricted, by reducing the encryption key strength or overwriting an authenticated key with an unauthenticated key,” according to a security advisory on Wednesday by the Carnegie Mellon CERT Coordination Center.

There are two types of Bluetooth protocols related to the attack – the older Bluetooth Classic (also known as Bluetooth Basic Rate/Enhanced Data Rate, or BR/EDR) and newer Bluetooth Low Energy (BLE). While BR/EDR are mainly used for audio applications such as wireless telephone connections, wireless headphones and wireless speakers, BLE is more often seen in wearable devices, smart IoT devices, fitness monitoring equipment and battery-powered accessories such as a keyboard.

Read more: https://threatpost.com/bluetooth-bug-mit...ks/159124/
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Messages In This Thread
Bluetooth Bug Opens Devices to Man-in-the-Middle Attacks - by silversurfer - 10 September 20, 18:34

Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Screenpresso 2.1.41
Screenpresso 2.1.4...harlan4096 — 10:37
QOwnNotes
26.3.2  Moved the...Kool — 10:02
XnView 2.52.5
XnView 2.52.5: ...harlan4096 — 09:22
AVG 26.2.10802 & Avast 26.2.10802
AVG 26.2.10802: ...harlan4096 — 08:15
K-Lite Codec Pack 19.5.5 / 19.5.5 Update
Changes in 19.5.5:...harlan4096 — 08:13

[-]
Birthdays
Today's Birthdays
No birthdays today.
Upcoming Birthdays
avatar (44)gapedDow
avatar (38)snorydar
avatar (43)Hectorvot
avatar (51)knowhanPluts
avatar (39)Williamengiz
avatar (46)qaqapeti
avatar (44)battsourIonix
avatar (43)CedricSek
avatar (39)chasRex
avatar (43)slavrProck
avatar (45)Tyesharaike
avatar (49)TomeRerla
avatar (45)walllMIZ
avatar (41)oconyho
avatar (33)uteluxix
avatar (47)piafcflene
avatar (39)Matthewkah
avatar (51)tersfargum
avatar (50)alfreExept
avatar (38)Charlesfibre
avatar (42)napasvem
avatar (44)diploJeoca
avatar (38)francisnj3
avatar (43)artmaGoork
avatar (45)tukraNax
avatar (41)RichardCisee
avatar (40)ebenofit
avatar (38)ykazawu
avatar (41)ARYsahulatbazar

[-]
Online Staff
There are no staff members currently online.

>