CVE-2020-26557 PUBLISHED

Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device (without possession of the AuthValue used in the provisioning protocol) to determine the AuthValue via a brute-force attack (unless the AuthValue is sufficiently random and changed each time).

EPSS 0.95% · 76.2th percentile

Risk Scores

EPSS Score
0.95%
76.2th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:Realtime:22.04:LTSlinux-intel-iot-realtime5.15.0-1036.38, 5.15.0-1037.39, 5.15.0-1038.40
Ubuntu:22.04:LTSlinux-kvm5.15.0-1034.39, 5.13.0-1007.7+22.04.1, 5.13.0-1006.6+22.04.1
Ubuntu:22.04:LTSlinux-gcp-5.19*, 5.19.0-1030.32~22.04.1, 5.19.0-1027.29~22.04.1
Ubuntu:22.04:LTSlinux-oracle5.15.0-1053.59, 5.15.0-1052.58, 5.15.0-1051.57
Ubuntu:Pro:18.04:LTSlinux-gcp-5.45.4.0-1046.49~18.04.1, 5.4.0-1049.53~18.04.1, 5.4.0-1051.55~18.04.1
Ubuntu:25.10linux-realtime6.14.0-1002.2, 0, 6.17.0-1006.7
Ubuntu:Pro:18.04:LTSlinux-gcp-4.154.15.0-1166.183, 4.15.0-1088.101, 4.15.0-1091.104
Ubuntu:20.04:LTSlinux-riscv-5.11*, 5.11.0-1030.34, 5.11.0-1028.31~20.04.1
Ubuntu:Pro:18.04:LTSlinux4.15.0-184.194, 4.13.0-16.19, 4.13.0-17.20
Ubuntu:Pro:16.04:LTSlinux4.4.0-219.252, 4.4.0-224.257, 4.4.0-229.263
Ubuntu:20.04:LTSlinux-intel-5.135.13.0-1017.19, 5.13.0-1014.15, 0
Ubuntu:22.04:LTSlinux-intel-iotg5.15.0-1037.42, 5.15.0-1084.90, 5.15.0-1088.94
Ubuntu:24.04:LTSlinux-oracle6.8.0-1022.23, 6.8.0-1021.22, 6.8.0-1023.24
Ubuntu:24.04:LTSlinux-riscv-6.170, 6.17.0-14.14.1~24.04.1
Ubuntu:22.04:LTSlinux-ibm-6.86.8.0-1036.36~22.04.1, *, *
Ubuntu:24.04:LTSlinux-raspi-realtime0, 6.8.0-2019.20
Ubuntu:Pro:Realtime:24.04:LTSlinux-realtime6.8.1-1024.25, 6.8.1-1023.24, 6.8.1-1022.23
Ubuntu:22.04:LTSlinux-nvidia5.15.0-1067.68, 5.15.0-1059.60, 5.15.0-1040.40
Ubuntu:22.04:LTSlinux-hwe-6.86.8.0-59.61~22.04.1, 6.8.0-65.68~22.04.1, 6.8.0-78.78~22.04.1
Ubuntu:Pro:Realtime:24.04:LTSlinux-realtime-6.146.14.0-1003.3~24.04.3, 6.14.0-1017.17~24.04.1, 6.14.0-1016.16~24.04.1

…and 219 more

Timeline

References

Open in Interactive Console →