Reflection attack on passkey entry
Description
Reflection attack on passkey entryRisk Assesment: 4.2
CWE
CVE
Attack Surfaces
Security Manager Protocol (MITRE EMB3D PID-4113)
Attack Vectors
Authentication challenge reflection (MITRE EMB3D TID-221)
Defenses
Restrict accepted public keys, Abort pairing if the remote public key is identical to the device's local one.