Description
SMP security request (from peripheral) does not include the maximum
encryption key size supported. Using a key with less than the maximum keysize
makes brute-forcing the key easier. See V6 in BLERP paper linked below.
Published: 2026-08-13
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability lies in the Simple Management Protocol (SMP) security request issued by a peripheral. The request does not include the maximum encryption key size that the device supports, allowing an attacker to specify a smaller key length. This reduction directly weakens the cryptographic protection of the link, making key recovery through brute‑force attacks significantly more feasible. The weakness can be identified as CWE‑521, which concerns inadequate key length or size.

Affected Systems

The flaw affects Silabs WiseConnect devices. No specific firmware or hardware revision numbers are listed in the CNA data; check the vendor documentation for the impact on your deployment.

Risk and Exploitability

The CVSS score is 8.8, indicating high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Attackers would need to send a tailored SMP security request from a peripheral or a compromised device that can interact directly with the target, implying local or proximity access. Once the smaller key size is negotiated, brute‑forcing the key becomes practicable, potentially exposing the session data and enabling further exploitation.

Generated by OpenCVE AI on August 13, 2026 at 16:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Silabs WiseConnect firmware revision that enforces the maximum encryption key size during SMP negotiations.
  • Verify that key negotiation on deployed devices uses the maximum key length by conducting SMP integrity tests.
  • Configure or restrict peripheral interfaces to prevent unauthorized or malformed SMP security requests from being accepted.

Generated by OpenCVE AI on August 13, 2026 at 16:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 14 Aug 2026 10:00:00 +0000

Type Values Removed Values Added
First Time appeared Silabs.com
Silabs.com wiseconnect
Vendors & Products Silabs.com
Silabs.com wiseconnect

Thu, 13 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 13 Aug 2026 15:15:00 +0000

Type Values Removed Values Added
Description SMP security request (from peripheral) does not include the maximum encryption key size supported. Using a key with less than the maximum keysize makes brute-forcing the key easier. See V6 in BLERP paper linked below.
Title SMP security request
Weaknesses CWE-521
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Silabs.com Wiseconnect
cve-icon MITRE

Status: PUBLISHED

Assigner: Silabs

Published:

Updated: 2026-08-13T17:06:08.921Z

Reserved: 2026-08-07T16:21:06.928Z

Link: CVE-2026-19293

cve-icon Vulnrichment

Updated: 2026-08-13T17:05:18.319Z

cve-icon NVD

Status : Received

Published: 2026-08-13T15:19:37.873

Modified: 2026-08-13T18:17:24.230

Link: CVE-2026-19293

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-14T09:31:27Z

Weaknesses
  • CWE-521

    Weak Password Requirements