Description
A malformed Bluetooth connection request message can cause the BT122 to leak potentially sensitive information. See vulnerability B-E4 in the related paper below.
Published: 2026-08-13
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A malformed Bluetooth connection request message can trigger the BT122 to leak potentially sensitive information. The flaw originates from improper handling of an increased length field in the packet, leading to a buffer over‑read (CWE‑126). When an attacker sends a crafted request, the device may read memory beyond the requested bounds and expose that data, although there is no evidence of code execution or denial of service. The CVSS score of 5.3 indicates a moderate severity.

Affected Systems

Silabs BT122 transceivers are the affected devices. No specific firmware version is listed in the CVE data, so the vulnerability may affect all available firmware versions until an update is released.

Risk and Exploitability

The EPSS score is not available, so the field‑level exploitation probability cannot be quantified; however, the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a spoofed Bluetooth connection request within range of the device, which would trigger the memory leak. Once triggered, the leaked data could be captured by an attacker with physical or wireless proximity, potentially exposing internal memory contents or configuration data. Because the flaw involves a malformed packet, an attacker does not need privileged access to invoke it, meaning the risk is operational rather than privileged.

Generated by OpenCVE AI on August 13, 2026 at 17:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest firmware update for the Silabs BT122 that corrects the packet length handling.
  • Configure the Bluetooth subsystem to reject connection requests with length fields that exceed protocol limits, thereby preventing the buffer over‑read.
  • If a firmware update is unavailable, isolate the BT122 from untrusted networks and monitor for anomalous memory usage patterns to detect exploitation attempts.

Generated by OpenCVE AI on August 13, 2026 at 17:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 14 Aug 2026 10:00:00 +0000

Type Values Removed Values Added
First Time appeared Silabs.com
Silabs.com bt122
Vendors & Products Silabs.com
Silabs.com bt122

Thu, 13 Aug 2026 15:15:00 +0000

Type Values Removed Values Added
Description A malformed Bluetooth connection request message can cause the BT122 to leak potentially sensitive information. See vulnerability B-E4 in the related paper below.
Title BT122 malformed packet with increased length field causes memory leak
Weaknesses CWE-126
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Silabs.com Bt122
cve-icon MITRE

Status: PUBLISHED

Assigner: Silabs

Published:

Updated: 2026-08-13T17:10:32.978Z

Reserved: 2026-07-23T15:47:23.376Z

Link: CVE-2026-65933

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-13T15:19:56.003

Modified: 2026-08-13T18:18:07.103

Link: CVE-2026-65933

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-14T09:31:22Z

Weaknesses