CVE-2026-19293CWE-521
CVE-2026-19293
High · published August 13, 2026
What it is
SMP security request (from peripheral) does not include the maximum
encryption key size supported. Using a key with less than the maximum keysize
makes brute-forcing the key easier. See V6 in BLERP paper linked below.
The record
Technical detail
- CVSS v3.1
- 8.8 · HIGH
- Vector
- CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- CVSS v4.0
- Not supplied
- EPSS
- 0.00134 · 3.2th percentile
- Weakness
- CWE-521 · Weak Password Requirements
- Published
- 2026-08-13T19:19Z
References (4)
EPSS history
Timeline
13 AUG 14:18Z
SMP security request
cvelistv5