CVE-2026-19293

8.8

silabs.com · WiseConnect

The Silabs WiseConnect platform fails to include maximum encryption key size information in SMP security requests, leading to potential weaknesses in Bluetooth Low Energy pairing.

Executive summary

A Bluetooth security flaw in the Silabs WiseConnect platform allows for potential encryption bypasses during peripheral pairing processes.

Vulnerability

The vulnerability relates to weak security requirements (CWE-521) where the peripheral fails to specify the maximum encryption key size during the Security Manager Protocol (SMP) exchange. This can facilitate re-pairing attacks or the negotiation of weaker-than-expected encryption keys.

Business impact

This vulnerability impacts the confidentiality and integrity of communications between Bluetooth-enabled devices. A CVSS score of 8.8 indicates a high risk, as attackers within proximity could intercept, modify, or decrypt sensitive data transmitted over the wireless link, potentially leading to unauthorized access to connected hardware or networks.

Remediation

Immediate Action: Update the WiseConnect SDK to version 4.1.0 or 2.14.0 respectively, as directed by the Silabs release notes.

Proactive Monitoring: Monitor wireless traffic for anomalous pairing requests or repeated handshake failures that may indicate an active attack attempt.

Compensating Controls: Where possible, enforce application-level encryption for sensitive data to provide a layer of protection independent of the underlying transport security.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Due to the nature of Bluetooth-based attacks, which are often local and difficult to detect, organizations should prioritize updating their firmware and SDK versions to address this encryption negotiation defect. Maintaining current software versions is essential for protecting devices that rely on the WiseConnect platform.