Impact
A re-pairing process with a legitimate device can be performed at a lower security level than the original pairing. The lower level reduces the strength of the Long Term Key, making it easier for an attacker to brute force the key. This weakness is defined as CWE‑305, reflecting improper handling of security settings during re‑authentication.
Affected Systems
Silicon Labs WiseConnect devices are affected. No specific firmware or hardware revisions are listed in the CNA data; only the product line is identified.
Risk and Exploitability
The CVSS score of 8.8 indicates a high impact when the flaw is exploited. The EPSS score is not available, so the current exploitation probability cannot be quantified. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector involves a Bluetooth connection; an adversary who can initiate or force a re‑pairing session with a legitimate device can exploit the downgrade to perform a brute‑force attack on the LTK. Because the flaw reduces cryptographic strength rather than creating a new attack surface, the overall risk remains high for any device using legacy pairing protocols.
OpenCVE Enrichment