CVE-2020-26560

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
24/05/2021
Last modified:
04/11/2025

Description

Bluetooth Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device, reflecting the authentication evidence from a Provisioner, to complete authentication without possessing the AuthValue, and potentially acquire a NetKey and AppKey.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:bluetooth:mesh_profile:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:bluetooth:mesh_profile:1.0.1:*:*:*:*:*:*:*