Bluetooth Pairing Access Restriction Bypass via Crafted NFC Tag

Bluetooth Pairing Access Restriction Bypass via Crafted NFC Tag

CVE-2014-7914 · HIGH Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

btif/src/btif_dm.c in Android before 5.1 does not properly enforce the temporary nature of a Bluetooth pairing, which allows user-assisted remote attackers to bypass intended access restrictions via crafted Bluetooth packets after the tapping of a crafted NFC tag.

Learn more about our Cis Benchmark Audit For Google Android.