Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-26559

Опубликовано: 24 мая 2021
Источник: nvd
CVSS3: 8.8
CVSS2: 5.8
EPSS Низкий

Описание

Bluetooth Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device (participating in the provisioning protocol) to identify the AuthValue used given the Provisioner’s public key, and the confirmation number and nonce provided by the provisioning device. This could permit a device without the AuthValue to complete provisioning without brute-forcing the AuthValue.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:bluetooth:mesh_profile:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:bluetooth:mesh_profile:1.0.1:*:*:*:*:*:*:*

EPSS

Процентиль: 82%
0.01652
Низкий

8.8 High

CVSS3

5.8 Medium

CVSS2

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 4 лет назад

Bluetooth Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device (participating in the provisioning protocol) to identify the AuthValue used given the Provisioner’s public key, and the confirmation number and nonce provided by the provisioning device. This could permit a device without the AuthValue to complete provisioning without brute-forcing the AuthValue.

CVSS3: 8.8
redhat
больше 4 лет назад

Bluetooth Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device (participating in the provisioning protocol) to identify the AuthValue used given the Provisioner’s public key, and the confirmation number and nonce provided by the provisioning device. This could permit a device without the AuthValue to complete provisioning without brute-forcing the AuthValue.

CVSS3: 8.8
github
больше 3 лет назад

Bluetooth Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device (participating in the provisioning protocol) to identify the AuthValue used given the Provisioner’s public key, and the confirmation number and nonce provided by the provisioning device. This could permit a device without the AuthValue to complete provisioning without brute-forcing the AuthValue.

EPSS

Процентиль: 82%
0.01652
Низкий

8.8 High

CVSS3

5.8 Medium

CVSS2

Дефекты

CWE-863