---
title: "CVE-2020-9770\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2020-9770?format=md
keywords: index, follow
---

# CVE-2020-9770

Publication date 1 April 2020

Last updated 11 July 2025

---

Ubuntu priority

**Low**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**6.5 · Medium**

[Score breakdown](https://ubuntu.com/security/CVE-2020-9770?format=md#impact-score)

Toggle side navigation

## Description

A logic issue was addressed with improved state management. This issue is
fixed in iOS 13.4 and iPadOS 13.4. An attacker in a privileged network
position may be able to intercept Bluetooth traffic.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2020-9770?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| bluez | 26.04 LTS resolute | Vulnerable, fix deferred |
| 25.10 questing | Ignored end of life, was deferred |
| 25.04 plucky | Ignored end of life, was deferred |
| 24.10 oracular | Ignored end of life, was deferred |
| 24.04 LTS noble | Vulnerable, fix deferred |
| 23.10 mantic | Ignored end of life, was deferred |
| 23.04 lunar | Ignored end of life, was deferred |
| 22.10 kinetic | Ignored end of life, was deferred |
| 22.04 LTS jammy | Vulnerable, fix deferred |
| 21.10 impish | Ignored end of life |
| 21.04 hirsute | Ignored end of life |
| 20.10 groovy | Ignored end of life |
| 20.04 LTS focal | Vulnerable, fix deferred |
| 18.04 LTS bionic | Vulnerable, fix deferred |
| 16.04 LTS xenial | Vulnerable, fix deferred |
| 14.04 LTS trusty | Not in release |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Notes

---

### [alexmurray](https://launchpad.net/~alexmurray)

For Ubuntu this only appears to affect gatttool from bluez. Marking this as low priority since this tool is not running or enabled by default (and is deprecated in favour of bluetoothctl).

---

### [mdeslaur](https://launchpad.net/~mdeslaur)

no upstream fix as of 2021-05-26

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

6.5 · Medium

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Network |
  | Attack complexity | Low |
  | Privileges required | Low |
  | User interaction | None |
  | Scope | Unchanged |
  | Confidentiality impact | High |
  | Integrity impact | None |
  | Availability impact | None |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 6.5 · Medium |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-9770)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2020-9770)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2020-9770)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2020-9770)

### Other references

* <https://support.apple.com/HT211102>
* <https://friends.cs.purdue.edu/pubs/WOOT20.pdf>
* <https://www.cve.org/CVERecord?id=CVE-2020-9770>
