Bluetooth Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device (participating in the provisioning protocol) to identify the AuthValue used given the Provisioner’s public key, and the confirmation number and nonce provided by the provisioning device. This could permit a device without the AuthValue to complete provisioning without brute-forcing the AuthValue.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2021-05-24T17:13:12

Updated: 2024-08-04T15:56:04.538Z

Reserved: 2020-10-04T00:00:00

Link: CVE-2020-26559

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-05-24T18:15:07.960

Modified: 2024-11-21T05:20:04.907

Link: CVE-2020-26559

cve-icon Redhat

Severity : Moderate

Publid Date: 2021-05-24T16:00:00Z

Links: CVE-2020-26559 - Bugzilla