CVE Published: 12/01/2021 |
CVE Updated: 08/10/2024 |
CVE Year: 2021 Source: microsoft |
Vendor: Microsoft |
Product: Windows 10 Version 20H2 Status : PUBLISHED
CVE-2021-1683 Description
Microsoft is aware of the "Impersonation in the Passkey Entry Protocol" vulnerability. For more information regarding the vulnerability, please see this statement from the Bluetooth SIG.
To address the vulnerability, Microsoft has released a software update that will fail attempts to pair if the remote device exchanges a public key with the same X coordinate as the locally exchanged public key
Metrics
CVSS Version: 3.1 |
Base Score: 5 MEDIUM Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C