CVE-2021-1684

medium

Description

Microsoft is aware of the "Impersonation in the Passkey Entry Protocol" vulnerability. For more information regarding the vulnerability, please see this statement from the Bluetooth SIG. To address the vulnerability, Microsoft has released a software update that will fail attempts to pair if the remote device exchanges a public key with the same X coordinate as the locally exchanged public key

References

https://www.tenable.com/blog/microsoft-s-january-2021-patch-tuesday-addresses-83-cves

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-1684

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-1684

Details

Source: Mitre, NVD

Published: 2021-01-12

Updated: 2024-11-21

Risk Information

CVSS v2

Base Score: 2.1

Vector: CVSS2#AV:L/AC:L/Au:N/C:P/I:N/A:N

Severity: Low

CVSS v3

Base Score: 5.5

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Severity: Medium