CVE-2020-26558: Bluetooth Core Specification
Medium severity, CVSS 4.2. EPSS: 0.9% chance of exploitation in the next 30 days.
Bluetooth LE and BR/EDR secure pairing in Bluetooth Core Specification 2.1 through 5.2 may permit a nearby man-in-the-middle attacker to identify the Passkey used during pairing (in the Passkey authentication procedure) by reflection of the public key and the authentication evidence of the initiating device, potentially permitting this attacker to complete authenticated pairing with the responding device using the correct Passkey for the pairing session. The attack methodology determines the Passkey value one bit at a time.
Affected products
- Bluetooth Bluetooth Core Specification: from 2.1, up to and including 5.2
- Debian Debian Linux: version 9.0 only
- Fedoraproject Fedora: version 34 only
- Intel Ac 1550 Firmware: affected versions not specified
- Intel Ac 3165 Firmware: affected versions not specified
- Intel Ac 3168 Firmware: affected versions not specified
- Intel Ac 7265 Firmware: affected versions not specified
- Intel Ac 8260 Firmware: affected versions not specified
- Intel Ac 8265 Firmware: affected versions not specified
- Intel Ac 9260 Firmware: affected versions not specified
- Intel Ac 9461 Firmware: affected versions not specified
- Intel Ac 9462 Firmware: affected versions not specified
- Intel Ac 9560 Firmware: affected versions not specified
- Intel AX1650 Firmware: affected versions not specified
- Intel AX1675 Firmware: affected versions not specified
- Intel AX200 Firmware: affected versions not specified
- Intel AX201 Firmware: affected versions not specified
- Intel AX210 Firmware: affected versions not specified
- Linux Linux Kernel: before 5.13 (fixed in 5.13)
Published 2021-05-24. Last modified 2026-06-17.