Vulnerability Description
Nordic Semiconductor Android BLE Library through 2.2.1 and DFU Library through 1.10.4 for Android (as used by nRF Connect and other applications) can engage in unencrypted communication while showing the user that the communication is purportedly encrypted. The problem is in bond creation (e.g., internalCreateBond in BleManagerHandler).
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Nordicsemi | Android Ble Library | <= 2.2.1 |
| Nordicsemi | Dfu Library | <= 1.10.4 |
Related Weaknesses (CWE)
References
- https://github.com/NordicSemiconductor/Android-BLE-Library/commits/masterPatchThird Party Advisory
- https://github.com/NordicSemiconductor/Android-DFU-Library/commits/releasePatchThird Party Advisory
- https://secretdiary.ninja/index.php/2020/07/03/norec-attack-stripping-ble-encrypPatchThird Party Advisory
- https://github.com/NordicSemiconductor/Android-BLE-Library/commits/masterPatchThird Party Advisory
- https://github.com/NordicSemiconductor/Android-DFU-Library/commits/releasePatchThird Party Advisory
- https://secretdiary.ninja/index.php/2020/07/03/norec-attack-stripping-ble-encrypPatchThird Party Advisory
FAQ
What is CVE-2020-15509?
CVE-2020-15509 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Nordic Semiconductor Android BLE Library through 2.2.1 and DFU Library through 1.10.4 for Android (as used by nRF Connect and other applications) can engage in unencrypted communication while showing ...
How severe is CVE-2020-15509?
CVE-2020-15509 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-15509?
Check the references section above for vendor advisories and patch information. Affected products include: Nordicsemi Android Ble Library, Nordicsemi Dfu Library.