CVE-2026-19293
Received Received - Intake

SMP Security Request Missing Maximum Encryption Key Size

Vulnerability report for CVE-2026-19293, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-13

Last updated on: 2026-08-13

Assigner: Silicon Graphics (SGI)

Description

SMP security request (from peripheral)Β does not include the maximum encryption key size supported. Using a key with less than the maximum keysize makes brute-forcing the key easier. See V6 in BLERP paper linked below.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-13
Last Modified
2026-08-13
Generated
2026-08-13
AI Q&A
2026-08-13
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
silicon_labs siwx91x_bluetooth_le_sdk 4.1.0
silicon_labs rs9116_bluetooth_le_sdk 2.14.1

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-521 The product does not require that users should have strong passwords.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves the SMP security request in Bluetooth Low Energy (BLE) not including the maximum encryption key size supported. Using a key smaller than the maximum makes brute-forcing easier. It is part of a broader issue in BLE re-pairing mechanisms where security flaws allow impersonation and Man-in-the-Middle attacks.

Impact Analysis

An attacker could exploit this to intercept or manipulate BLE communications, potentially gaining unauthorized access to devices or data. The vulnerability enables impersonation and MitM attacks with minimal user interaction, affecting all standard-compliant BLE devices using pairing.

Mitigation Strategies

Update to the latest SDK version (4.1.0 or later) for Silicon Labs SiWx91x Bluetooth LE SDK to enable the rsi_ble_vendor_set_SMP_min_enc_keysize API and set a minimum encryption key size between 7 and 16 bytes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-19293. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart