CAPEC Definitions

    CAPEC Definitions / CAPEC-667

    CAPEC-667: Bluetooth Impersonation AttackS (BIAS)

    An adversary disguises the MAC address of their Bluetooth enabled device to one for which there exists an active and trusted connection and authenticates successfully. The adversary can then perform malicious actions on the target Bluetooth device depending on the target’s capabilities.

    Severity:High
    Possibility:Medium

    Extended Description

    No Extended Description.

    Mitigations

    Disable Bluetooth in public places.

    Verify incoming Bluetooth connections; do not automatically trust.

    Change default PIN passwords and always use one when connecting.

    Relationships with other CAPECs

    CAPEC-616: Establish Rogue Location

    Prerequisites

    Knowledge of a target device's list of trusted connections.

    Related Weaknesses

    CWE-290: Authentication Bypass by Spoofing