TopVuln

High-risk vulnerability digests

CVE-2020-15802

  • MEDIUM

Exploit for Improper Restriction of Operations within the Bounds of a Memory Buffer in Google Android

Details

CVSS v3
5.9
CVSS v2
4.3
NVD published
2020-09-11 14:15:11
EPSS
55.5% probability · 98.0th percentile — 2026-03-20
Affected versions
cpe:2.3:a:bluetooth:bluetooth_core_specification:*:*:*:*:*:*:*:*
Summary
Devices supporting Bluetooth before 5.1 may allow man-in-the-middle attacks, aka BLURtooth. Cross Transport Key Derivation in Bluetooth Core Specification v4.2 and v5.0 may permit an unauthenticated user to establish a bonding with one transport, either LE or BR/EDR, and replace a bonding already established on the opposing transport, BR/EDR or LE, potentially overwriting an authenticated key with an unauthenticated key, or a key with greater entropy with one with less.
Remediation
Not available in our cache.
Exploit info
Not available in our cache.

View on NVD

TopVuln sends digest emails with high-risk CVE picks across multiple authoritative sources—curated with EPSS and AI. Choose daily per-stream emails and optional weekly or monthly roundups.

Subscribe — free email digest or paid plan

Information is aggregated from multiple authoritative sources for convenience; verify with NVD and vendors before operational decisions.