#VU22622 Cleartext transmission of sensitive information in BCM20702
Published: November 10, 2019
BCM20702
Broadcom
Description
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to software firmware does not use encryption during communication via Bluetooth protocol. An attacker with physical proximity to the device can intercept network traffic can gain access to sensitive data, (e.g. perform a person-in-the-middle attack).
Remediation
Cybersecurity Help is currently unaware of any official solution to address this vulnerability.
Please, contact your hardware vendor to obtain patches.