CVE-2026-19293CWE-521

CVE-2026-19293

High · published August 13, 2026

CVSS v3.1
8.8
EPSS
0%
Percentile
3.2
In the wild
Unconfirmed
What it is

SMP security request (from peripheral) does not include the maximum

encryption key size supported. Using a key with less than the maximum keysize

makes brute-forcing the key easier. See V6 in BLERP paper linked below.

The record
Technical detail
CVSS v3.1
8.8 · HIGH
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.00134 · 3.2th percentile
Weakness
CWE-521 · Weak Password Requirements
Published
2026-08-13T19:19Z
References (4)
EPSS history
Timeline
  • 13 AUG 14:18Z
    SMP security request
    cvelistv5