"-Synchronized-Data."

This commit is contained in:
CVE Team 2020-06-03 09:01:17 +00:00
parent a3a56fb7ae
commit e8e511eaa8
No known key found for this signature in database
GPG Key ID: 5708902F06FEF743
2 changed files with 11 additions and 1 deletions

View File

@ -38,7 +38,7 @@
"description_data": [
{
"lang": "eng",
"value": "Legacy pairing and secure-connections pairing authentication in Bluetooth® BR/EDR Core Specification v5.2 and earlier may allow an unauthenticated user to complete authentication without pairing credentials via adjacent access. An unauthenticated, adjacent attacker could impersonate a Bluetooth BR/EDR master or slave to pair with a previously paired remote device to successfully complete the authentication procedure without knowing the link key."
"value": "Legacy pairing and secure-connections pairing authentication in Bluetooth\u00ae BR/EDR Core Specification v5.2 and earlier may allow an unauthenticated user to complete authentication without pairing credentials via adjacent access. An unauthenticated, adjacent attacker could impersonate a Bluetooth BR/EDR master or slave to pair with a previously paired remote device to successfully complete the authentication procedure without knowing the link key."
}
]
},
@ -89,6 +89,11 @@
"name": "https://www.bluetooth.com/learn-about-bluetooth/bluetooth-technology/bluetooth-security/bias-vulnerability/",
"refsource": "CONFIRM",
"url": "https://www.bluetooth.com/learn-about-bluetooth/bluetooth-technology/bluetooth-security/bias-vulnerability/"
},
{
"refsource": "FULLDISC",
"name": "20200602 BIAS (Bluetooth Impersonation Attack) CVE 2020-10135 reproduction",
"url": "http://seclists.org/fulldisclosure/2020/Jun/5"
}
]
},

View File

@ -83,6 +83,11 @@
"refsource": "MLIST",
"name": "[debian-lts-announce] 20200528 [SECURITY] [DLA 2209-1] tomcat8 security update",
"url": "https://lists.debian.org/debian-lts-announce/2020/05/msg00026.html"
},
{
"refsource": "FULLDISC",
"name": "20200602 [CVE-2020-9484] Apache Tomcat RCE via PersistentManager",
"url": "http://seclists.org/fulldisclosure/2020/Jun/6"
}
]
},