{"id":"CVE-2026-19293","title":"SMP security request (from peripheral) does not include the maximum\nencryption key size supported","summary":"SMP security request (from peripheral) does not include the maximum\nencryption key size supported. Using a key with less than the maximum keysize\nmakes brute-forcing the key easier. See V6 in BLERP paper linked below.","severity":"high","cvss":8.8,"cvssVector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-521"],"published":"2026-08-13","updated":"2026-09-08","sourceUpdated":"2026-09-08T19:12:59.557","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-19293","references":[{"url":"https://community.silabs.com/068Vm00000x0yyH","label":"product-security@silabs.com"},{"url":"https://docs.silabs.com/rs9116-wiseconnect/latest/wifibt-wc-release-notes/rs9116-ble-release-notes#bug-fixes","label":"product-security@silabs.com"},{"url":"https://docs.silabs.com/sisdk-release-notes/latest/sisdk-wifi-release-notes/sisdk-wifible-ble-release-notes","label":"product-security@silabs.com"},{"url":"https://www.ndss-symposium.org/ndss-paper/blerp-ble-re-pairing-attacks-and-defenses/","label":"product-security@silabs.com"}],"tags":["nvd"],"epss":0.00134,"epssPercentile":0.03292,"ingestedAt":"2026-09-08T20:10:03.157Z","slug":"CVE-2026-19293","body":"## Overview\n\nSMP security request (from peripheral) does not include the maximum\nencryption key size supported. Using a key with less than the maximum keysize\nmakes brute-forcing the key easier. See V6 in BLERP paper linked below.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":48,"depthScoreParts":{"impact":48.4,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}