Cloud Defense Logo

Products

Solutions

Company

Book A Live Demo

CVE-2020-35693 : Security Advisory and Response

Learn about CVE-2020-35693, a security flaw on Samsung devices running Android through 7.1.1, allowing unauthorized Bluetooth pairing. Find mitigation steps and affected devices.

A vulnerability exists on certain Samsung devices running Android through version 7.1.1, allowing an attacker-controlled Bluetooth Low Energy (BLE) device to pair silently with a vulnerable target device.

Understanding CVE-2020-35693

This CVE highlights a security issue that enables unauthorized pairing of Bluetooth devices without user interaction, potentially leading to long-term tracking of affected devices.

What is CVE-2020-35693?

The vulnerability allows an attacker's BLE device to pair with a vulnerable Samsung device silently, exchanging personally identifiable information during the process.

The Impact of CVE-2020-35693

        Attackers can pair with vulnerable devices without user consent, posing a privacy risk.
        Personally identifiable information is exchanged, enabling potential long-term tracking.

Technical Details of CVE-2020-35693

This section provides more in-depth technical insights into the vulnerability.

Vulnerability Description

        Vulnerable Samsung devices running Android through 7.1.1 are susceptible to unauthorized BLE pairing.

Affected Systems and Versions

        Devices affected include Galaxy Note 5, Galaxy S6 Edge, Galaxy A3, Tab A (2017), J2 Pro (2018), Galaxy Note 4, and Galaxy S5.

Exploitation Mechanism

        An attacker-controlled BLE device can pair silently with vulnerable Samsung devices running specific Android versions.

Mitigation and Prevention

Protecting against CVE-2020-35693 requires immediate actions and long-term security practices.

Immediate Steps to Take

        Disable Bluetooth when not in use to prevent unauthorized pairing.
        Avoid using connectable BLE advertisements in public or untrusted environments.

Long-Term Security Practices

        Regularly update device firmware to patch known vulnerabilities.
        Be cautious when using Bluetooth in public places to minimize exposure to potential attacks.
        Consider using security apps that monitor Bluetooth connections for suspicious activities.

Patching and Updates

        Samsung may release security patches to address this vulnerability, so ensure your device is up to date with the latest software updates.

Popular CVEs

CVE Id

Published Date

Is your System Free of Underlying Vulnerabilities?
Find Out Now