CVE-2020-26558
Bluetooth LE and BR/EDR secure pairing in Bluetooth Core Specification 2.1 through 5.2 may permit a nearby man-in-the-middle attacker to identify the Passkey used during pairing (in the Passkey authentication procedure) by reflection of the public key and the authentication evidence of the initiating device, potentially permitting this attacker to complete authenticated pairing with the responding device using the correct Passkey for the pairing session. The attack methodology determines the Passkey value one bit at a time.
Published:May 24, 2021
Last Modified:Nov 4, 2025
EPS:May 24, 2021
EPSS Score:0.0002
CVSS Score:4.2
Affected Products
Vendor
Product
Action
Vendor
Bluetooth
Product
Bluetooth Core Specification
Bluetooth
Bluetooth Core Specification
Vendor
Debian
Product
Debian Linux
Debian
Debian Linux
Vendor
Fedoraproject
Product
Fedora
Fedoraproject
Fedora
Vendor
Intel
Product
Ac 1550
Intel
Ac 1550
Vendor
Intel
Product
Ac 1550 Firmware
Intel
Ac 1550 Firmware
Vendor
Intel
Product
Ac 3165
Intel
Ac 3165
Vendor
Intel
Product
Ac 3165 Firmware
Intel
Ac 3165 Firmware
Vendor
Intel
Product
Ac 3168
Intel
Ac 3168
Vendor
Intel
Product
Ac 3168 Firmware
Intel
Ac 3168 Firmware
Vendor
Intel
Product
Ac 7265
Intel
Ac 7265
Vendor
Intel
Product
Ac 7265 Firmware
Intel
Ac 7265 Firmware
Vendor
Intel
Product
Ac 8260
Intel
Ac 8260
Vendor
Intel
Product
Ac 8260 Firmware
Intel
Ac 8260 Firmware
Vendor
Intel
Product
Ac 8265
Intel
Ac 8265
Vendor
Intel
Product
Ac 8265 Firmware
Intel
Ac 8265 Firmware
Vendor
Intel
Product
Ac 9260
Intel
Ac 9260
Vendor
Intel
Product
Ac 9260 Firmware
Intel
Ac 9260 Firmware
Vendor
Intel
Product
Ac 9461
Intel
Ac 9461
Vendor
Intel
Product
Ac 9461 Firmware
Intel
Ac 9461 Firmware
Vendor
Intel
Product
Ac 9462
Intel
Ac 9462
Vendor
Intel
Product
Ac 9462 Firmware
Intel
Ac 9462 Firmware
Vendor
Intel
Product
Ac 9560
Intel
Ac 9560
Vendor
Intel
Product
Ac 9560 Firmware
Intel
Ac 9560 Firmware
Vendor
Intel
Product
Ax1650
Intel
Ax1650
Vendor
Intel
Product
Ax1650 Firmware
Intel
Ax1650 Firmware
Vendor
Intel
Product
Ax1675
Intel
Ax1675
Vendor
Intel
Product
Ax1675 Firmware
Intel
Ax1675 Firmware
Vendor
Intel
Product
Ax200
Intel
Ax200
Vendor
Intel
Product
Ax200 Firmware
Intel
Ax200 Firmware
Vendor
Intel
Product
Ax201
Intel
Ax201
Vendor
Intel
Product
Ax201 Firmware
Intel
Ax201 Firmware
Vendor
Intel
Product
Ax210
Intel
Ax210
Vendor
Intel
Product
Ax210 Firmware
Intel
Ax210 Firmware
Vendor
Linux
Product
Linux Kernel
Linux
Linux Kernel
Vendor
Redhat
Product
Enterprise Linux
Redhat
Enterprise Linux
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
