#VU22622 Cleartext transmission of sensitive information in BCM20702

 

#VU22622 Cleartext transmission of sensitive information in BCM20702

Published: November 10, 2019


Vulnerability identifier: #VU22622
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: N/A
CWE-ID: CWE-319
Exploitation vector: Local access
Exploit availability: No public exploit available
Vulnerable software:
BCM20702
Software vendor:
Broadcom

Description

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to software firmware does not use encryption during communication via Bluetooth protocol. An attacker with physical proximity to the device can intercept network traffic can gain access to sensitive data, (e.g. perform a person-in-the-middle attack).


Remediation

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

Please, contact your hardware vendor to obtain patches.


External links