CVEs Blog | G5 Cyber Security

CVE-2020-26556 – Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit

Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device, able to conduct a successful brute-force attack on an insufficiently random AuthValue before the provisioning procedure times out, to complete authentication by leveraging Malleable Commitment.

 

Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-26556

Reference (s):

Exit mobile version