CVE-2020-35693 (CNNVD-202012-1540)
中文标题:
Samsung 多款产品安全漏洞
英文标题:
On some Samsung phones and tablets running Android through 7.1.1, it is possible for an attacker-con...
漏洞描述
中文描述:
Samsung Galaxy S6和Samsung Galaxy S5都是韩国三星(Samsung)公司的一款智能手机。 Samsung phones 存在安全漏洞,当目标设备的蓝牙开启时,由攻击者控制的低功耗蓝牙(BLE)设备有可能与易受攻击的目标设备静默配对,而无需任何用户交互, 并且它正在运行一个提供可连接BLE广告的应用程序。以下产品及版本受到影响: Galaxy Note 5, Galaxy S6 Edge, Galaxy A3, Tab A (2017), J2 Pro (2018), Galaxy Note 4, and Galaxy S5。
英文描述:
On some Samsung phones and tablets running Android through 7.1.1, it is possible for an attacker-controlled Bluetooth Low Energy (BLE) device to pair silently with a vulnerable target device, without any user interaction, when the target device's Bluetooth is on, and it is running an app that offers a connectable BLE advertisement. An example of such an app could be a Bluetooth-based contact tracing app, such as Australia's COVIDSafe app, Singapore's TraceTogether app, or France's TousAntiCovid (formerly StopCovid). As part of the pairing process, two pieces (among others) of personally identifiable information are exchanged: the Identity Address of the Bluetooth adapter of the target device, and its associated Identity Resolving Key (IRK). Either one of these identifiers can be used to perform re-identification of the target device for long term tracking. The list of affected devices includes (but is not limited to): Galaxy Note 5, Galaxy S6 Edge, Galaxy A3, Tab A (2017), J2 Pro (2018), Galaxy Note 4, and Galaxy S5.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| android | * | - | - |
cpe:2.3:o:google:android:*:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
参考链接
cve.org
CVSS评分详情
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2020-35693 |
2025-11-11 15:20:35 | 2025-11-11 07:36:20 |
| NVD | nvd_CVE-2020-35693 |
2025-11-11 14:57:07 | 2025-11-11 07:44:44 |
| CNNVD | cnnvd_CNNVD-202012-1540 |
2025-11-11 15:10:33 | 2025-11-11 07:56:32 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 其他
- cnnvd_id: 未提取 -> CNNVD-202012-1540
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- severity: SeverityLevel.MEDIUM -> SeverityLevel.HIGH
- cvss_score: 未提取 -> 8.8
- cvss_vector: NOT_EXTRACTED -> CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- cvss_version: NOT_EXTRACTED -> 3.1
- affected_products_count: 0 -> 1
- data_sources: ['cve'] -> ['cve', 'nvd']