CVE-2020-26557

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
24/05/2021
Last modified:
04/11/2025

Description

Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device (without possession of the AuthValue used in the provisioning protocol) to determine the AuthValue via a brute-force attack (unless the AuthValue is sufficiently random and changed each time).

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:bluetooth:mesh_profile:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:bluetooth:mesh_profile:1.0.1:*:*:*:*:*:*:*