Learn about CVE-2020-35473, a vulnerability in Bluetooth Core Specifications allowing identification of devices using Resolvable Private Addressing (RPA) through scan responses. Find mitigation steps and prevention measures.
Bluetooth Low Energy Advertisement Scan Response Information Leakage Vulnerability
Understanding CVE-2020-35473
An information leakage vulnerability in Bluetooth Low Energy advertisement scan response in Bluetooth Core Specifications 4.0 through 5.2 allows for the identification of devices using Resolvable Private Addressing (RPA) by their response to specific scan requests.
What is CVE-2020-35473?
The vulnerability in Bluetooth Core Specifications 4.0 through 5.2, and extended scan response in Bluetooth Core Specifications 5.0 through 5.2, enables the identification of devices using RPA through their responses to scan requests.
The Impact of CVE-2020-35473
Technical Details of CVE-2020-35473
Vulnerability Description
The vulnerability lies in the Bluetooth Low Energy advertisement scan response, potentially exposing devices using RPA to identification through scan requests.
Affected Systems and Versions
Exploitation Mechanism
The vulnerability allows malicious actors to identify devices using RPA by analyzing their responses to specific scan requests.
Mitigation and Prevention
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates