Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jrvv-3x7m-vqjc

Опубликовано: 14 мая 2024
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

An issue was discovered on certain Nuki Home Solutions devices. Some BLE commands, which should have been designed to be only called from privileged accounts, could also be called from unprivileged accounts. This demonstrates that no access controls were implemented for the different BLE commands across the different accounts. This affects Nuki Smart Lock 3.0 before 3.3.5 and Nuki Smart Lock 2.0 before 2.12.4.

An issue was discovered on certain Nuki Home Solutions devices. Some BLE commands, which should have been designed to be only called from privileged accounts, could also be called from unprivileged accounts. This demonstrates that no access controls were implemented for the different BLE commands across the different accounts. This affects Nuki Smart Lock 3.0 before 3.3.5 and Nuki Smart Lock 2.0 before 2.12.4.

EPSS

Процентиль: 19%
0.00059
Низкий

8.8 High

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 8.8
nvd
больше 1 года назад

An issue was discovered on certain Nuki Home Solutions devices. Some BLE commands, which should have been designed to be only called from privileged accounts, could also be called from unprivileged accounts. This demonstrates that no access controls were implemented for the different BLE commands across the different accounts. This affects Nuki Smart Lock 3.0 before 3.3.5 and Nuki Smart Lock 2.0 before 2.12.4.

EPSS

Процентиль: 19%
0.00059
Низкий

8.8 High

CVSS3

Дефекты

CWE-284