Menu

Database

Static Bluetooth PIN codes

WVE ID: WVE-2005-0009

Type: Vulnerability

Status: Candidate

Classification:
Authentication Management
Design Flaw

Description:
Bluetooth devices that have no means for PIN code input come with a hard-coded PIN to use when pairing with another device.

Discussion:
The primary authentication mechanism used in Bluetooth devices is a PIN, between 1 and 16 characters in length, that is used to authenticate a device for the first time. However, many Bluetooth devices have no means for inputting a user-defined PIN code when pairing with another device, due to the lack of a man-machine interface (MMI) such as a numeric keypad or keyboard. This is especially prevalent in Bluetooth headsets, pointing devices, headphones, and speakers.

To get around this limitation, such devices make use of a hard-coded PIN that may be entered into a peer device when pairing is initiated. This itself is not a problem. However, many of these devices use the same PIN code for every unit of a particular model of device that is produced. Thus, it is trivial for someone to guess the PIN used by one of the affected devices for a pairing with any given device based on its make and model. Once someone has determined the correct PIN, they can use it to gain unauthorized access to the vulnerable device.

Credits

References
URL: http://www.jabra.com/JabraCMS/NA/EN/MainMenu/Products/WirelessHeadsets/JabraBT160/JabraBT160.htm
URL: http://www.starcom1.com/bluetooth.htm

Released: 2000-01-01

Submitter
Andrew Lockhart (alockhart@networkchemistry.com) : Network Chemistry

Submitted: Tue Oct 18 14:26:17 -0700 2005

Candidate Date: Mon Oct 24 10:01:54 -0700 2005


Recent Entries

TKIP Replay and Plaintext Discovery
WVE-2008-0013 11/18/2008

Active Https Cookie Hijacking
WVE-2008-0012 9/18/2008

Auto Immune Attack
WVE-2008-0011 9/17/2008

Marvell Null SSID Association Request
WVE-2008-0010 9/15/2008

Marvell EAPOL-Key Length Overflow
WVE-2008-0009 9/15/2008

Atheros IE Tag Overflow
WVE-2008-0008 9/15/2008

Weaknesses in the A5/1 Cipher
WVE-2008-0007 4/9/2008

Block ACK DoS
WVE-2008-0006 4/9/2008

GF Mode WIDS Rogue AP Evasion
WVE-2008-0005 4/9/2008

HT Intolerant Degradation of Service
WVE-2008-0004 4/9/2008

More Entries...

News

SANS Institute Sponsors WVE
4/19/2008

Wireless Attackers and Honeypot Technology
4/15/2008

High Speed Risks in 802.11n Slides Posted
4/11/2008

Vulnerabilities in 802.11n
4/9/2008

WVE Editors Speaking at SHARKFEST.08
1/3/2008

More News...