Cleartext transmission of sensitive information in BCM20702 - #VU22622

 

Cleartext transmission of sensitive information in BCM20702 - #VU22622

Published: November 10, 2019


Vulnerability identifier: #VU22622
CSH Severity: Low
CVSS v4: 2.4 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-319
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to software firmware does not use encryption during communication via Bluetooth protocol. An attacker with physical proximity to the device can intercept network traffic can gain access to sensitive data, (e.g. perform a person-in-the-middle attack).


Affected software

BCM20702
Opensuse

Remediation

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

Please, contact your hardware vendor to obtain patches.



External References

Related Security Bulletins