CAPEC Definitions
CAPEC Definitions / CAPEC-667
CAPEC-667: Bluetooth Impersonation AttackS (BIAS)
An adversary disguises the MAC address of their Bluetooth enabled device to one for which there exists an active and trusted connection and authenticates successfully. The adversary can then perform malicious actions on the target Bluetooth device depending on the target’s capabilities.
Severity:High
Possibility:Medium
Extended Description
No Extended Description.
Mitigations
Disable Bluetooth in public places.
Verify incoming Bluetooth connections; do not automatically trust.
Change default PIN passwords and always use one when connecting.
Relationships with other CAPECs
CAPEC-616: Establish Rogue Location
Prerequisites
Knowledge of a target device's list of trusted connections.
Related Weaknesses
CWE-290: Authentication Bypass by Spoofing
