Get a Pentest and security assessment of your IT network.

2021-current

CVE-2020-11957 – The Bluetooth Low Energy implementation in Cypress PSoC Creator BLE 4.2 c

The Bluetooth Low Energy implementation in Cypress PSoC Creator BLE 4.2 component versions before 3.64 generates a random number (Pairing Random) with significantly less entropy than the specified 128 bits during BLE pairing. This is the case for both authenticated and unauthenticated pairing with both LE Secure Connections as well as LE Legacy Pairing. A predictable or brute-forceable random number allows an attacker (in radio range) to perform a MITM attack during BLE pairing.

 

Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-11957

Reference (s):

  • https://www.cypress.com/file/504466/download
Related posts
2021-current

CVE-2004-1715 - Directory traversal vulnerability in MIMEsweeper for Web before 5.0.4 all

2021-current

CVE-2014-7793 - The CB - Calciatori Brutti (aka com.calciatori.brutti) application 1.0 fo

2021-current

CVE-2019-9721 - A denial of service in the subtitle decoder in FFmpeg 3.2 and 4.1 allows

2021-current

CVE-2020-13653 - An XSS vulnerability exists in the Webmail component of Zimbra Collaborat