Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Nordicsemi Subscribe
Filtered by product Android Ble Library
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-15509 1 Nordicsemi 2 Android Ble Library, Dfu Library 2021-07-21 3.3 LOW 6.5 MEDIUM
Nordic Semiconductor Android BLE Library through 2.2.1 and DFU Library through 1.10.4 for Android (as used by nRF Connect and other applications) can engage in unencrypted communication while showing the user that the communication is purportedly encrypted. The problem is in bond creation (e.g., internalCreateBond in BleManagerHandler).