Home

Awesome

Awesome Bluetooth Security (BR, EDR, LE, and Mesh)

Awesome

This list links to useful references for anyone working with Bluetooth BR/EDR/LE or Mesh security.

Submit a PR if something is missing!

To Do


Contents


<a name="notable_vulnerabilities"></a>Notable Vulnerabilities

Vulnerability nameConference & Year publishedVulnerability website URLPaper URLVideo URLSIG NoticeTechnology ImpactedRelated CVE
BlueBorneBlack Hat Europe 2017SitePaperVideoNo NoticeBR/EDRCVE-2017-8628, CVE-2017-0781, CVE-2017-0782, CVE-2017-0783, CVE-2017-0785, CVE-2017-14315, CVE-2017-1000250, CVE-2017-1000251, CVE-2017-14315, CVE-2017-1000410
Bleedingbit2018SitePaperVideoNo NoticeLECVE-2018-7080, CVE-2018-16986
Fixed Coordinate Invalid Curve Attack2018SitePaperVideoSIG NoticeBR/EDR/LECVE-2018-5383
SweynTooth2019SitePaperVideoNo NoticeLECVE-2019-16336, CVE-2019-17060, CVE-2019-17061, CVE-2019-17517, CVE-2019-17518, CVE-2019-17519, CVE-2019-17520, CVE-2019-19192, CVE-2019-19193, CVE-2019-19194, CVE-2019-19195, CVE-2019-19196, CVE-2020-10061, CVE-2020-10069, CVE-2020-13593, CVE-2020-13594, CVE-2020-13595
KNOBUSENIX 2019SitePaperVideoSIG NoticeBR/EDRCVE-2019-9506
BIASIEEE S&P 2020SitePaperVideoSIG NoticeBR/EDRCVE-2020-10135
Pairing Method Confusion2020SitePaperNo VideoSIG NoticeBR/EDR/LECVE-2020-10134
BlueFrag2020ArticleNo PaperNo VideoNo NoticeAndroidCVE-2020-0022
SpectraBlack Hat USA 2020AbstractTBDVideoNo NoticeWiFi+BT modulesCVE-2019-15063, CVE-2020-10367, CVE-2020-10368, CVE-2020-10369, CVE-2020-10370
BLURtooth2020SitePaperVideoSIG NoticeBR/EDR+LECVE-2020-15802, CVE-2022-20361
BLESAWOOT 2020SitePaperVideoNo NoticeLECVE-2020-9770
BleedingTooth2020SiteWriteupVideoNo NoticeLinuxCVE-2020-12351, CVE-2020-12352, CVE-2020-24490
BlueMirrorWOOT 2021SitePaperVideoMultiple SIG NoticesBR/EDR/LE/MeshCVE-2020-26555, CVE-2020-26556, CVE-2020-26557, CVE-2020-26558, CVE-2020-26559, CVE-2020-26560
InjectaBLEIEEE DSN 2021SitePaperNo VideoSIG NoticeLECVE-2021-31615
BrakTooth2021SitePaperVideoNo NoticeBR/EDRCVE-2021-28135, CVE-2021-28136, CVE-2021-28139, CVE-2021-28155, CVE-2021-31717, CVE-2021-31609, CVE-2021-31611, CVE-2021-31612, CVE-2021-31613, CVE-2021-31785, CVE-2021-31786, CVE-2021-31610, CVE-2021-34143, CVE-2021-34144, CVE-2021-34145, CVE-2021-34146, CVE-2021-34147, CVE-2021-34148, CVE-2021-34149, CVE-2021-34150
Pairing Mode Confusion2022No SiteNo PaperNo VideoSIG NoticeLECVE-2022-25836
Pairing Mode Confusion2022No SiteNo PaperNo VideoSIG NoticeBR/EDRCVE-2022-25837
BLUFFS2023SitePaperNo VideoSIG NoticeBR/EDRCVE-2023-24023

<a name="conference_talks"></a>Conference Talks

2003

2004

2005

2006

2007

2009

2010

2011

2012

2013

2014

2015

2016

2017

2018

2019

2020

2021


<a name="bluetooth_security_tools"></a>Bluetooth Security Tools

Linux Utilities & Tools

Scanners & Sniffers

Exploit Tools

OBEX Attack Tools

Fuzzing

Firmware Analysis

Man-in-the-middle & Packet Injection

Device Spoofing

Ping & Signal Strength Tools

Denial of Service

Honeypot

Android Apps

Hardware

Other


<a name="primary_references"></a>Primary Reference Materials

Bluetooth Core Specifications Link

NIST Special Publication (SP) 800-121 revision 2 Link


<a name="useful_sites"></a>Useful Sites