BLE v4.2 Should be secure against replay attacks, but not secure against MitM attacks.
According to this post, it uses a counter along with signatures to stop replay attacks.
However, BLE v4.2 still (to my understanding) is vulnerable to MitM attacks, this post mentions that the attacks from WOOT 2013 still apply to Bluetooth 4.2.
This article talks about the security enhancements of BLE v4.2 over 4.1 and two possible attacks on Bluetooth 4.2.
There are also new attacks against Bluetooth user devices which have been discovered in the past month which I recommend taking a look at (both are :
- BLURtooth: allows an attacker to perform device impersonation, traffic manipulation, and malicious session establishment.
- BLESA: which enable an attacker to impersonate a BLE device and to provide spoofed data to another previously paired device