Pairing in Bluetooth® Core v5.2 and earlier may permit an unauthenticated attacker to acquire credentials with two pairing devices via adjacent access when the unauthenticated user initiates different pairing methods in each peer device and an end-user erroneously completes both pairing procedures with the MITM using the confirmation number of one peer as the passkey of the other. An adjacent, unauthenticated attacker could be able to initiate any Bluetooth operation on either attacked device exposed by the enabled Bluetooth profiles. This exposure may be limited when the user must authorize certain access explicitly, but so long as a user assumes that it is the intended remote device requesting permissions, device-local protections may be weakened.
Conclusion & alert: CVE-2020-10134 is rated Moderate Risk (42/100): CVSS Medium severity, with low exploitation likelihood (EPSS 0.66%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.13% | 0.66% | +0.53% |
| 2 | 2026-04-07 | 0.15% | 0.13% | -0.03% |
| 3 | 2026-02-10 | — | 0.15% | — |
Full EPSS history (14 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 6.3 | 3.1 | MEDIUM |
|
2.1 | 4.2 | [email protected] |
| 6.3 | 3.1 | MEDIUM |
|
2.1 | 4.2 | [email protected] |
| 4.3 | 2.0 | MEDIUM |
|
5.5 | 4.9 | [email protected] |
| vendor | priority | summary | link |
|---|---|---|---|
redhat
|
medium | — | https://access.redhat.com/security/cve/CVE-2020-10134 |
suse
|
medium | CVE-2020-10134 severity moderate: SUSE including 5 source package names (bluez, bluez-cups, bluez-deprecated, bluez-devel, libbluetooth3), 65 product×package rows across 33 product lines (SUSE Enterprise Storage 7, SUSE Linux Enterprise High Performance Computing 12 SP5, … (33 product lines)): Will Not Fix 65. | https://www.suse.com/security/cve/CVE-2020-10134/ |
ubuntu
|
medium | CVE-2020-10134 medium priority: Ubuntu including 1 source packages (bluez), 17 status rows across 17 suites (bionic, eoan, focal, groovy, hirsute, impish, jammy, kinetic, lunar, mantic, noble, oracular, plucky, questing, trusty, upstream, xenial): ignored 9, deferred 6, DNE 1, needs-triage 1. | https://ubuntu.com/security/CVE-2020-10134 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| bluetooth | bluetooth_core | <= 5.2 | cpe:2.3:a:bluetooth:bluetooth_core:*:*:*:*:br:*:*:* |
| bluetooth | bluetooth_core | <= 5.2 | cpe:2.3:a:bluetooth:bluetooth_core:*:*:*:*:edr:*:*:* |
| bluetooth | bluetooth_core | <= 5.2 | cpe:2.3:a:bluetooth:bluetooth_core:*:*:*:*:le:*:*:* |
| URL | Tags |
|---|---|
| https://kb.cert.org/vuls/id/534195/ | Third Party Advisory US Government Resource |
| https://www.bluetooth.com/learn-about-bluetooth/bluetooth-technology/bluetooth-security/method-vulnerability/ | Vendor Advisory |