CVE-2020-26558 - CVE House
Back to Database
Status published Medium CVE-2020-26558

Bluetooth LE and BR/EDR secure pairing in Bluetooth Core Specification...

Vulnerability Description

Bluetooth LE and BR/EDR secure pairing in Bluetooth Core Specification 2.1 through 5.2 may permit a nearby man-in-the-middle attacker to identify the Passkey used during pairing (in the Passkey authentication procedure) by reflection of the public key and the authentication evidence of the initiating device, potentially permitting this attacker to complete authenticated pairing with the responding device using the correct Passkey for the pairing session. The attack methodology determines the Passkey value one bit at a time.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-26558

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

bluetooth core specification, fedora, debian linux, linux kernel, ax210 firmware, ax201 firmware, ax200 firmware, ac 9560 firmware, ac 9462 firmware, ac 9461 firmware, ac 9260 firmware, ac 8265 firmware, ac 8260 firmware, ac 3168 firmware, ac 7265 firmware, ac 3165 firmware, ax1675 firmware, ax1650 firmware, ac 1550 firmware
Vulnerable Versions:
2.1, 34, 9.0, 0

Timeline

Official Publish: May 24th, 2021
Last Modified: November 4th, 2025
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.