Vulnerabilities in nRF5 SDK versions

Security Threat in Bluetooth® LESC Pairing

There is a distinction between software-only implementations that rely solely on the cryptographic routines expressed as compilable software or linkable libraries, and hardware-accelerated implementations that rely on specialized hardware for the cryptographic routines required for the LE Secure Connections pairing procedure. Here the differences are explained in relation to SDK versions.

LE Secure Connections are supported in the S130 and S132 SoftDevice v2.0.0 or later and in all versions of the S112 and S140 SoftDevice. There is no requirement to change the SoftDevice version on a device to address any issues of vulnerability, the changes are solely in the nRF5 SDK source code. There is a distinction between versions prior to v15.0.0 and later with regards to the vulnerability.