ShadowTrackr

Search the CVE vulnerability database

Look up vulnerabilities by software, product or CVE number.

← Back to results

CVE-2020-26558

Bluetooth LE and BR/EDR secure pairing in Bluetooth Core Specification 2.1 through 5.2 may permit a nearby man-in-the-middle attacker to identify the Passkey used during pairing (in the Passkey authentication procedure) by reflection of the public key and the authentication evidence of the initiating device, potentially permitting this attacker to complete authenticated pairing with the responding device using the correct Passkey for the pairing session. The attack methodology determines the Passkey value one bit at a time.
4.2
CVSS
1.3
ShadowTrackr
NO
CISA KEV
-
NCSC.nl
CVSS v4.0 Metrics
Exploitability
Attack VectorAdjacent
ComplexityHigh
RequirementsPresent
PrivilegesNone
User InteractionNone
Threat
Exploit MaturityPoC
Vulnerable System
ConfidentialityLow
IntegrityLow
AvailabilityNone
Subsequent System
ConfidentialityNone
IntegrityNone
AvailabilityNone
Supplemental
SafetyNegligible
AutomatableYes
RecoveryAutomatic
Value DensityConcentrated
UrgencyMedium
Patch StatusUnavailable

Change Log
DateSourceChangesScore
2026-07-21PoCE: U→P0.6 → 1.3
2026-07-21nvdAV: P→A, PR: H→N, UI: A→N, VC: N→L, VI: N→L0.0 → 0.6
2026-07-21cve.orginitial, patch: Unavailable0.0

Affected Software
VendorProductVersion
bluetoothbluetooth_core_specification≥ 2.1, ≤ 5.2
debiandebian_linux9.0
fedoraprojectfedora34
intelac_1550_firmwareAll versions
intelac_3165_firmwareAll versions
intelac_3168_firmwareAll versions
intelac_7265_firmwareAll versions
intelac_8260_firmwareAll versions
intelac_8265_firmwareAll versions
intelac_9260_firmwareAll versions
intelac_9461_firmwareAll versions
intelac_9462_firmwareAll versions
intelac_9560_firmwareAll versions
intelax1650_firmwareAll versions
intelax1675_firmwareAll versions
intelax200_firmwareAll versions
intelax201_firmwareAll versions
intelax210_firmwareAll versions
linuxlinux_kernel≤ 5.13
Published: 2021-05-24