<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://devzone.nordicsemi.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Vulnerability Note</title><link>https://devzone.nordicsemi.com/f/nordic-q-a/36838/vulnerability-note</link><description>Hi, 
 The following vulnerability described as Bluetooth implementations may not sufficiently validate elliptic curve parameters during Diffie-Hellman key exchange in the following page was recently published: 
 https://www.kb.cert.org/vuls/id/304725</description><dc:language>en-US</dc:language><generator>Telligent Community 13</generator><lastBuildDate>Tue, 04 Sep 2018 10:32:52 GMT</lastBuildDate><atom:link rel="self" type="application/rss+xml" href="https://devzone.nordicsemi.com/f/nordic-q-a/36838/vulnerability-note" /><item><title>RE: Vulnerability Note</title><link>https://devzone.nordicsemi.com/thread/147148?ContentTypeID=1</link><pubDate>Tue, 04 Sep 2018 10:32:52 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:1a8f4de6-e150-45c6-9e2e-eb35a8888c86</guid><dc:creator>Einar Thorsrud</dc:creator><description>&lt;p&gt;Hi,&lt;/p&gt;
&lt;p&gt;BLE Mesh is not affected in any way. This issue only concerns LE Secure Connections (LESC) which is not used in BLE Mesh.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Vulnerability Note</title><link>https://devzone.nordicsemi.com/thread/147066?ContentTypeID=1</link><pubDate>Tue, 04 Sep 2018 03:10:43 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:afc28e46-d053-4f4b-8c5c-cd5946e68fd6</guid><dc:creator>Bob J</dc:creator><description>&lt;p&gt;Hi&lt;/p&gt;
&lt;p&gt;I was wondering how this affects BLE Mesh. If I was using SDK 14 but using NFC to transfer the DHEC parameters, would there still be a vulnerability? Or would the vulnerability only exist if I was not using NFC.&lt;/p&gt;
&lt;p&gt;I read the white paper and it did not appear to address this question.&lt;/p&gt;
&lt;p&gt;Thanks in advance for responding.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Vulnerability Note</title><link>https://devzone.nordicsemi.com/thread/141595?ContentTypeID=1</link><pubDate>Fri, 27 Jul 2018 05:53:31 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:a91ee722-8a9b-4f45-b28e-253d851c06bd</guid><dc:creator>Einar Thorsrud</dc:creator><description>&lt;p&gt;Hi,&lt;/p&gt;
&lt;p&gt;We just published a white paper which describe this issue in detail: &lt;a href="https://infocenter.nordicsemi.com/topic/nwp_031/WP/nwp_031/intro.html"&gt;nWP031 - Security Threat in Bluetooth LESC Pairing&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;In a nutshell, the problem is that the Bluetooth specification did not require that the remote public key be validated before it is used to calculate the shared secret during the Diffie&amp;ndash;Hellman key exchange. The LE Secure Connection implementation for Nordic devices reside in SDK &amp;quot;space&amp;quot; rather than in the SoftDevice (stack), so this issue can be fixed in the SDK. The fix is to always validate the remote public key before it is used to generate the shared secret. This issue is&amp;nbsp;not present in SDK 15.0.0, which always validates the remote public in the &lt;a href="https://infocenter.nordicsemi.com/topic/com.nordic.infocenter.sdk5.v15.0.0/group__ble__lesc.html"&gt;BLE LESC module&lt;/a&gt;.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Vulnerability Note</title><link>https://devzone.nordicsemi.com/thread/141397?ContentTypeID=1</link><pubDate>Wed, 25 Jul 2018 16:03:50 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:2bbb3e62-b840-4bed-b121-5d0c44508f48</guid><dc:creator>Jim Dattolo</dc:creator><description>&lt;p&gt;I came here to ask the same thing, can someone from Nordic chime in with a list of SD versions that have been checked for this vulnerability?&amp;nbsp; I&amp;#39;m currently on SDK14 SD 5.1.0 on a NRF52832 chip.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>