ZeroHour

CVE-2020-15509

CVSS 3.1
6.5 medium
EPSS
<1%p44
Published
()
Modified
Description

Nordic Semiconductor Android BLE Library through 2.2.1 and DFU Library through 1.10.4 for Android (as used by nRF Connect and other applications) can engage in unencrypted communication while showing the user that the communication is purportedly encrypted. The problem is in bond creation (e.g., internalCreateBond in BleManagerHandler).

Vendors
nordicsemi
Products
android ble library, dfu library
Weakness
CWE-319
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.