Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Mobile Security //

Bluetooth

7/25/2018
08:05 AM
Larry Loeb
Larry Loeb
Larry Loeb
50%
50%

Bluetooth Vulnerability Opens Up Man-in-the-Middle Attacks

With almost certainly hypothetical, this vulnerability in Bluetooth's protocol could result in a man-in-the-middle attack and allow the culprits to steal personal data off a device.

The Bluetooth Special Interest Group (SIG) has updated the specifications of the protocol to deal with a high severity vulnerability in some implementations that could compromise data integrity.

The Secure Simple Pairing and LE Secure Connections are the affected parts of the protocol, according to the update. When pairing with a new device, the protocol "recommends, but does not require" validation of the public key received during that pairing.

Researchers Lior Neumann and Eli Biham of the Israel Institute of Technology discovered in January that this was not being implemented by all vendors. If ignored, the pairing devices would not validate the elliptic curve parameters which generated public keys during a Diffie-Hellman key exchange.

This could result in a weak key being injected by an attacker that is within physical range of the pairing devices. This injected fake key would then be accepted by the devices, giving rise to the attacker being able to mount a man-in-the-middle (MiM) attack.

(Source: Wikimedia)\r\n
(Source: Wikimedia)\r\n

The Bluetooth SIG notes in the statement that the attack -- which has not been found in the wild -- requires some stringent conditions.

SIG notes:

For an attack to be successful, an attacking device would need to be within wireless range of two vulnerable Bluetooth devices that were going through a pairing procedure. The attacking device would need to intercept the public key exchange by blocking each transmission, sending an acknowledgement to the sending device, and then injecting the malicious packet to the receiving device within a narrow time window. If only one device had the vulnerability, the attack would not be successful.

The attack has been listed as CVE-2018-5383.

US Computer Emergency Readiness Team (US-CERT) has also sent out a security advisory about the problem. In it, CERT listed Apple, Broadcom, Intel and Qualcomm as being affected by the vulnerability. All four say they have deployed some sort of fix.

Microsoft is listed as not being affected. The CERT notice found that it could not determine if Android, other types of Google devices, or the Linux kernel was affected.


Zero in on the most attractive 5G NR deployment strategies, and take a look ahead to later technology developments and service innovations. Join us for the Deployment Strategies for 5G NR breakfast workshop in LA at MWCA on September 12. Register now to learn from and network with industry experts – communications service providers get in free!

CERT describes the solution that has been put into place.

"Since the vulnerability was identified," according to the July 23 advisory, "the Bluetooth SIG has updated the Bluetooth specifications to require validation of any public key received as part of public key-based security procedures, thereby providing a remedy to the vulnerability from a specification perspective. In addition, the Bluetooth SIG has added testing for this vulnerability within its Bluetooth Qualification Program."

Since it has been about six months between discovery of the flaw and remediation, there has been enough time to complete a comprehensive solution. The underlying problem is simple enough: Trust but verify that the proposed actions should take care of the vulnerability when the vendors issue their needed patches.

Related posts:

— Larry Loeb has written for many of the last century's major "dead tree" computer magazines, having been, among other things, a consulting editor for BYTE magazine and senior editor for the launch of WebWeek.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Edge-DRsplash-10-edge-articles
I Smell a RAT! New Cybersecurity Threats for the Crypto Industry
David Trepp, Partner, IT Assurance with accounting and advisory firm BPM LLP,  7/9/2021
News
Attacks on Kaseya Servers Led to Ransomware in Less Than 2 Hours
Robert Lemos, Contributing Writer,  7/7/2021
Commentary
It's in the Game (but It Shouldn't Be)
Tal Memran, Cybersecurity Expert, CYE,  7/9/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
How Enterprises are Attacking the Cybersecurity Problem
Concerns over supply chain vulnerabilities and attack visibility drove some significant changes in enterprise cybersecurity strategies over the past year. Dark Reading's 2021 Strategic Security Survey showed that many organizations are staying the course regarding the use of a mix of attack prevention and threat detection technologies and practices for dealing with cyber threats.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-34761
PUBLISHED: 2021-10-27
A vulnerability in Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to overwrite or append arbitrary data to system files using root-level privileges. The attacker must have administrative credentials on the device. This vulnerability is due to incomplete v...
CVE-2021-34762
PUBLISHED: 2021-10-27
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to perform a directory traversal attack on an affected device. The attacker would require valid device credentials. The vulnerability is due to ins...
CVE-2021-34763
PUBLISHED: 2021-10-27
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an attacker to execute a cross-site scripting (XSS) attack or an open redirect attack. For more information about these vulnerabilities, see the Details section of this adv...
CVE-2021-34764
PUBLISHED: 2021-10-27
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an attacker to execute a cross-site scripting (XSS) attack or an open redirect attack. For more information about these vulnerabilities, see the Details section of this adv...
CVE-2021-34781
PUBLISHED: 2021-10-27
A vulnerability in the processing of SSH connections for multi-instance deployments of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on the affected device. This vulnerability is due to a lack of proper err...