Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2vpv-3c94-j6hf

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

oBike relies on Hangzhou Luoping Smart Locker to lock bicycles, which allows attackers to bypass the locking mechanism by using Bluetooth Low Energy (BLE) to replay ciphertext based on a predictable nonce used in the locking protocol.

oBike relies on Hangzhou Luoping Smart Locker to lock bicycles, which allows attackers to bypass the locking mechanism by using Bluetooth Low Energy (BLE) to replay ciphertext based on a predictable nonce used in the locking protocol.

EPSS

Процентиль: 21%
0.00069
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-294

Связанные уязвимости

CVSS3: 5.3
nvd
больше 7 лет назад

oBike relies on Hangzhou Luoping Smart Locker to lock bicycles, which allows attackers to bypass the locking mechanism by using Bluetooth Low Energy (BLE) to replay ciphertext based on a predictable nonce used in the locking protocol.

EPSS

Процентиль: 21%
0.00069
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-294