#VU53582 Security features bypass in Bluetooth Mesh profile - CVE-2020-26557 

 

#VU53582 Security features bypass in Bluetooth Mesh profile - CVE-2020-26557

Published: May 26, 2021 / Updated: January 26, 2022


Vulnerability identifier: #VU53582
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2020-26557
CWE-ID: CWE-254
Exploitation vector: Adjecent network
Exploit availability: No public exploit available
Vulnerable software:
Bluetooth Mesh profile
Software vendor:
Bluetooth SIG, Inc.

Description

The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exists due to the use of predictable AuthValue in the Mesh Provisioning procedure. A remote attacker on the local network can perform a brute-force attack to obtain the AuthValue and authenticate to both the Provisioner and provisioned devices.


Remediation

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

External links