Description
The BT122 module stops advertising after receiving a plaintext 'pause enceryption response' message resulting in a denial of service. See vulnerability B-E2 in the related paper below.
Published: 2026-08-13
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The BT122 module ceases all advertising functions upon receipt of a plaintext 'pause enceryption response' message. This flaw immediately renders the device unadvertisable, resulting in an availability outage. The weakness is classified as CWE‑440, indicating improper handling of input that leads to a disrupt service.

Affected Systems

Silabs BT122 devices are affected. No specific version information was provided, so all current revisions of the BT122 module should be considered vulnerable until a vendor patch is released.

Risk and Exploitability

The CVSS score of 5.3 marks this as a moderate‑severity denial of service with limited impact. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. It is likely that an attacker must deliver the malicious plaintext message to the BT122 module over its control channel, which suggests a local‑network or device‑level attack vector. No remote exploitation pathway is documented in the provided description, so the likelihood of widespread exploitation remains uncertain.

Generated by OpenCVE AI on August 13, 2026 at 17:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the BT122 firmware to the latest version released by Silabs that includes the fix for the pause message handling issue.
  • If a firmware update is not immediately available, restrict or filter reception of plaintext 'pause enceryption response' messages to prevent the device from entering the advertising‑stop state.
  • Implement a monitoring routine that checks the advertising status of the BT122 module and automatically re‑enables advertising or restarts the device when a pause condition is detected.

Generated by OpenCVE AI on August 13, 2026 at 17:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 14 Aug 2026 10:00:00 +0000

Type Values Removed Values Added
First Time appeared Silabs.com
Silabs.com bt122
Vendors & Products Silabs.com
Silabs.com bt122

Thu, 13 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 13 Aug 2026 15:15:00 +0000

Type Values Removed Values Added
Description The BT122 module stops advertising after receiving a plaintext 'pause enceryption response' message resulting in a denial of service. See vulnerability B-E2 in the related paper below.
Title BT122 stops advertising
Weaknesses CWE-440
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Silabs.com Bt122
cve-icon MITRE

Status: PUBLISHED

Assigner: Silabs

Published:

Updated: 2026-08-13T17:08:07.477Z

Reserved: 2026-07-23T15:47:23.376Z

Link: CVE-2026-65932

cve-icon Vulnrichment

Updated: 2026-08-13T17:07:59.441Z

cve-icon NVD

Status : Received

Published: 2026-08-13T15:19:55.867

Modified: 2026-08-13T18:18:06.980

Link: CVE-2026-65932

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-14T09:31:25Z

Weaknesses
  • CWE-440

    Expected Behavior Violation