CVE-2020-26559 PUBLISHED

Bluetooth Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device (participating in the provisioning protocol) to identify the AuthValue used given the Provisioner’s public key, and the confirmation number and nonce provided by the provisioning device. This could permit a device without the AuthValue to complete provisioning without brute-forcing the AuthValue.

EPSS 1.27% · 79.4th percentile

Risk Scores

EPSS Score
1.27%
79.4th percentile

Affected Products

VendorProductVersions
Ubuntu:24.04:LTSlinux-azure-6.146.14.0-1012.12~24.04.1, 6.14.0-1013.13~24.04.1, 6.14.0-1017.17~24.04.1
Ubuntu:Pro:20.04:LTSlinux-gcp5.4.0-1157.166, 5.4.0-1148.157, 5.4.0-1117.126
Ubuntu:22.04:LTSlinux-azure5.15.0-1019.24, 5.15.0-1089.98, 5.15.0-1090.99
Ubuntu:18.04:LTSlinux-azure-5.35.3.0-1013.14~18.04.1, 5.3.0-1022.23~18.04.1, 5.3.0-1028.29~18.04.1
Ubuntu:22.04:LTSlinux-nvidia5.15.0-1063.64, 5.15.0-1005.5, 5.15.0-1007.7
Ubuntu:22.04:LTSlinux-azure-fde-5.195.19.0-1026.29~22.04.1.1, 0, 5.19.0-1027.30~22.04.2.1
Ubuntu:Pro:20.04:LTSlinux-oracle-5.15*, *, *
Ubuntu:22.04:LTSlinux-gcp-6.86.8.0-1010.11~22.04.1, 0, 6.8.0-1020.22~22.04.1
Ubuntu:24.04:LTSlinux-gkeop6.8.0-1011.13, 0, 6.8.0-1010.12
Ubuntu:24.04:LTSlinux-gcp-6.110, 6.11.0-1006.6~24.04.2, 6.11.0-1011.11~24.04.1
Ubuntu:22.04:LTSlinux-aws-6.8*, 0, 6.8.0-1009.9~22.04.2
Ubuntu:Pro:FIPS:20.04:LTSlinux-aws-fips5.4.0-1021.21+fips2, 0
Ubuntu:22.04:LTSlinux-nvidia-tegra5.15.0-1025.25, 5.15.0-1051.51, 5.15.0-1026.26
Ubuntu:20.04:LTSlinux-oem-5.145.14.0-1052.59, 5.14.0-1018.19, 5.14.0-1034.37
Ubuntu:Pro:FIPS-preview:22.04:LTSlinux-fips5.15.0-73.80+fips1, 0
Ubuntu:16.04:LTSlinux-hwe-edge4.15.0-15.16~16.04.1, 4.15.0-20.21~16.04.1, 4.15.0-22.24~16.04.1
Ubuntu:Pro:FIPS-updates:22.04:LTSlinux-fips5.15.0-142.152+fips1, *, *
Ubuntu:Pro:20.04:LTSlinux-nvidia-tegra-5.155.15.0-1041.41~20.04.1, *, *
Ubuntu:24.04:LTSlinux-azure-nvidia-6.140, 6.14.0-1003.3, 6.14.0-1006.6
Ubuntu:Pro:20.04:LTSlinux-aws5.4.0-1124.134, 5.4.0-1063.66, 5.4.0-1137.147

…and 219 more

Timeline

References

Open in Interactive Console →