Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r4j8-hwcx-q55j

Опубликовано: 15 мар. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

Sciener locks' firmware update mechanism do not authenticate or validate firmware updates if passed to the lock through the Bluetooth Low Energy service. A challenge request can be sent to the lock with a command to prepare for an update, rather than an unlock request, allowing an attacker to compromise the device.

Sciener locks' firmware update mechanism do not authenticate or validate firmware updates if passed to the lock through the Bluetooth Low Energy service. A challenge request can be sent to the lock with a command to prepare for an update, rather than an unlock request, allowing an attacker to compromise the device.

EPSS

Процентиль: 30%
0.00108
Низкий

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
nvd
почти 2 года назад

Sciener locks' firmware update mechanism do not authenticate or validate firmware updates if passed to the lock through the Bluetooth Low Energy service. A challenge request can be sent to the lock with a command to prepare for an update, rather than an unlock request, allowing an attacker to compromise the device.

EPSS

Процентиль: 30%
0.00108
Низкий

9.8 Critical

CVSS3