Related Vulnerabilities: CVE-2020-26557  

Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device (without possession of the AuthValue used in the provisioning protocol) to determine the AuthValue via a brute-force attack (unless the AuthValue is sufficiently random and changed each time).

Severity Medium

Remote Yes

Type Private key recovery

Description

Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device (without possession of the AuthValue used in the provisioning protocol) to determine the AuthValue via a brute-force attack (unless the AuthValue is sufficiently random and changed each time).

AVG-1881 linux-hardened 5.12.6.hardened1-1 Medium Vulnerable

AVG-1880 linux-zen 5.12.6.zen1-1 Medium Vulnerable

AVG-1879 linux 5.12.6.arch4-1 Medium Vulnerable

AVG-1741 linux-lts 5.10.40-1 Medium Vulnerable

https://bugzilla.redhat.com/show_bug.cgi?id=1960009
https://kb.cert.org/vuls/id/799380
https://www.bluetooth.com/learn-about-bluetooth/key-attributes/bluetooth-security/reporting-security/