Vulnslist

find the latest Cisco vulnerabilities

Key Negotiation of Bluetooth Vulnerability

cisco-sa-20190813-bluetooth · Medium · Published · Updated

A weakness in the Bluetooth Basic Rate/Enhanced Data Rate (BR/EDR) protocol core specification exposes a vulnerability that could allow for an unauthenticated, adjacent attacker to perform a man-in-the-middle attack on an encrypted Bluetooth connection. The attack must be performed during negotiation or renegotiation of a paired device connection; existing sessions cannot be attacked. The issue could allow the attacker to reduce the entropy of the negotiated session key that is used to secure a Bluetooth connection between a paired device and a host device. An attacker who can successfully inject a malicious message into a Bluetooth connection during session negotiation or renegotiation could cause the strength of the session key to be susceptible to brute force attack. This advisory will be updated as additional information becomes available. There are no workarounds that address this vulnerability. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190813-bluetooth

Cisco advisory · CSAF JSON

Workarounds

There are no workarounds that address this vulnerability.

CVEsCVE-2019-9506
Cisco Bug IDsCSCvq80515, CSCvq80439, CSCvq80433, CSCvq80441, CSCvq80432, CSCvq80431, CSCvq80426
CVSS ScoreBase 9.3
Base 9.3 CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N/E:X/RL:X/RC:X
Product Names From Source
Cisco IP Phone 8800 Series Software, Cisco Small Business IP Phones, Cisco TelePresence CE Software, Cisco IP Phone 8800 Series with Multiplatform Firmware

Related Products

Product CVE Evidence
Cisco TelePresence CE Software CVE-2019-9506 Cisco OpenVuln
Cisco TelePresence CVE-2019-9506 Cisco OpenVuln
Cisco Small Business IP Phones CVE-2019-9506 Cisco OpenVuln
Cisco IP phone CVE-2019-9506 Cisco OpenVuln
Cisco IP Phone 8800 Series with Multiplatform Firmware CVE-2019-9506 Cisco OpenVuln
Cisco IP Phone 8800 Series Software CVE-2019-9506 Cisco OpenVuln