ShadowTrackr

Search the CVE vulnerability database

Look up vulnerabilities by software, product or CVE number.

← Back to results

CVE-2020-16630

TI’s BLE stack caches and reuses the LTK’s property for a bonded mobile. A LTK can be an unauthenticated-and-no-MITM-protection key created by Just Works or an authenticated-and-MITM-protection key created by Passkey Entry, Numeric Comparison or OOB. Assume that a victim mobile uses secure pairing to pair with a victim BLE device based on TI chips and generate an authenticated-and-MITM-protection LTK. If a fake mobile with the victim mobile’s MAC address uses Just Works and pairs with the victim device, the generated LTK still has the property of authenticated-and-MITM-protection. Therefore, the fake mobile can access attributes with the authenticated read/write permission.
6.8
CVSS
4.9
ShadowTrackr
NO
CISA KEV
-
NCSC.nl
CVSS v4.0 Metrics
Exploitability
Attack VectorAdjacent
ComplexityHigh
RequirementsPresent
PrivilegesNone
User InteractionNone
Threat
Exploit MaturityUnreported
Vulnerable System
ConfidentialityHigh
IntegrityHigh
AvailabilityNone
Subsequent System
ConfidentialityNone
IntegrityNone
AvailabilityNone
Supplemental
SafetyNegligible
AutomatableYes
RecoveryAutomatic
Value DensityConcentrated
UrgencyMedium
Patch StatusUnavailable

Change Log
DateSourceChangesScore
2026-07-21nvdAV: P→A, PR: H→N, UI: A→N, VC: N→H, VI: N→H0.0 → 4.9
2026-07-21cve.orginitial, patch: Unavailable0.0

Affected Software
VendorProductVersion
ti15.4-stackAll versions
tible5-stackAll versions
tidynamic_multi-protocal_managerAll versions
tieasylinkAll versions
tiopenthreadAll versions
tireal-time_operating_systemAll versions
tiz-stackAll versions
Published: 2021-09-20