Description
Bluetooth Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device, reflecting the authentication evidence from a Provisioner, to complete authentication without possessing the AuthValue, and potentially acquire a NetKey and AppKey.
CVSS vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NExploitability: 2.8 | Impact: 5.2Attack Vector: Adjacent
Complexity: Low
Privileges: None
User Interaction: None
Scope: Unchanged
Confidentiality: High
Integrity: High
Availability: None
Affected Packages1 packages
🔴Vulnerability Details
3GHSAGHSA-8qgh-c754-3crv: Bluetooth Mesh Provisioning in the Bluetooth Mesh profile 1↗2022-05-24 ▶ CVEListCVE-2020-26560: Bluetooth Mesh Provisioning in the Bluetooth Mesh profile 1↗2021-05-24 ▶ OSVCVE-2020-26560: Bluetooth Mesh Provisioning in the Bluetooth Mesh profile 1↗2021-05-24 ▶ 📋Vendor Advisories
1Red Hatkernel: impersonation attack in Bluetooth Mesh Provisioning↗2021-05-24 ▶ 🕵️Threat Intelligence
2TalosVulnerability Spotlight: Multiple vulnerabilities in Synology DiskStation Manager↗2021-04-20 ▶ TalosVulnerability Spotlight: Multiple vulnerabilities in Synology DiskStation Manager↗2021-04-20 ▶