CVE Feed

    Dashboard / CVE / CVE-2020-26558

    CVE-2020-26558

    Bluetooth LE and BR/EDR secure pairing in Bluetooth Core Specification 2.1 through 5.2 may permit a nearby man-in-the-middle attacker to identify the Passkey used during pairing (in the Passkey authentication procedure) by reflection of the public key and the authentication evidence of the initiating device, potentially permitting this attacker to complete authenticated pairing with the responding device using the correct Passkey for the pairing session. The attack methodology determines the Passkey value one bit at a time.

    Published:May 24, 2021
    Last Modified:Nov 4, 2025
    EPS:May 24, 2021
    EPSS Score:0.0002
    CVSS Score:4.2

    Affected Products

    Vendor
    Bluetooth
    Product
    Bluetooth Core Specification
    Vendor
    Debian
    Product
    Debian Linux
    Vendor
    Fedoraproject
    Product
    Fedora
    Vendor
    Intel
    Product
    Ac 1550
    Vendor
    Intel
    Product
    Ac 1550 Firmware
    Vendor
    Intel
    Product
    Ac 3165
    Vendor
    Intel
    Product
    Ac 3165 Firmware
    Vendor
    Intel
    Product
    Ac 3168
    Vendor
    Intel
    Product
    Ac 3168 Firmware
    Vendor
    Intel
    Product
    Ac 7265
    Vendor
    Intel
    Product
    Ac 7265 Firmware
    Vendor
    Intel
    Product
    Ac 8260
    Vendor
    Intel
    Product
    Ac 8260 Firmware
    Vendor
    Intel
    Product
    Ac 8265
    Vendor
    Intel
    Product
    Ac 8265 Firmware
    Vendor
    Intel
    Product
    Ac 9260
    Vendor
    Intel
    Product
    Ac 9260 Firmware
    Vendor
    Intel
    Product
    Ac 9461
    Vendor
    Intel
    Product
    Ac 9461 Firmware
    Vendor
    Intel
    Product
    Ac 9462
    Vendor
    Intel
    Product
    Ac 9462 Firmware
    Vendor
    Intel
    Product
    Ac 9560
    Vendor
    Intel
    Product
    Ac 9560 Firmware
    Vendor
    Intel
    Product
    Ax1650
    Vendor
    Intel
    Product
    Ax1650 Firmware
    Vendor
    Intel
    Product
    Ax1675
    Vendor
    Intel
    Product
    Ax1675 Firmware
    Vendor
    Intel
    Product
    Ax200
    Vendor
    Intel
    Product
    Ax200 Firmware
    Vendor
    Intel
    Product
    Ax201
    Vendor
    Intel
    Product
    Ax201 Firmware
    Vendor
    Intel
    Product
    Ax210
    Vendor
    Intel
    Product
    Ax210 Firmware
    Vendor
    Linux
    Product
    Linux Kernel
    Vendor
    Redhat
    Product
    Enterprise Linux

    Exploits

    No exploit reference

    Common Weakness Enumeration

    Related CVEs

    References

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High