#VU53578 Improper access control in Bluetooth Core Specification - CVE-2020-26555
Published: May 26, 2021
Bluetooth Core Specification
Bluetooth SIG, Inc.
Description
The vulnerability allows a local attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions within the Bluetooth legacy BR/EDR PIN code pairing. An attacker with physical access can spoof the BD_ADDR of the peer device and complete pairing without knowledge of the PIN.