Impact
The vulnerability lies in the Simple Management Protocol (SMP) security request issued by a peripheral. The request does not include the maximum encryption key size that the device supports, allowing an attacker to specify a smaller key length. This reduction directly weakens the cryptographic protection of the link, making key recovery through brute‑force attacks significantly more feasible. The weakness can be identified as CWE‑521, which concerns inadequate key length or size.
Affected Systems
The flaw affects Silabs WiseConnect devices. No specific firmware or hardware revision numbers are listed in the CNA data; check the vendor documentation for the impact on your deployment.
Risk and Exploitability
The CVSS score is 8.8, indicating high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Attackers would need to send a tailored SMP security request from a peripheral or a compromised device that can interact directly with the target, implying local or proximity access. Once the smaller key size is negotiated, brute‑forcing the key becomes practicable, potentially exposing the session data and enabling further exploitation.
OpenCVE Enrichment