Описание
The Bluetooth Low Energy (BLE) subsystem on Tapplock devices before 2018-06-12 relies on Key1 and SerialNo for unlock operations; however, these are derived from the MAC address, which is broadcasted by the device.
Ссылки
- Vendor Advisory
- Third Party Advisory
- Vendor Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2018-06-12 (исключая)
Одновременно
cpe:2.3:o:tapplock:tapplock_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:tapplock:tapplock:-:*:*:*:*:*:*:*
EPSS
Процентиль: 27%
0.00095
Низкий
6.5 Medium
CVSS3
3.3 Low
CVSS2
Дефекты
CWE-200
Связанные уязвимости
CVSS3: 6.5
github
больше 3 лет назад
The Bluetooth Low Energy (BLE) subsystem on Tapplock devices before 2018-06-12 relies on Key1 and SerialNo for unlock operations; however, these are derived from the MAC address, which is broadcasted by the device.
EPSS
Процентиль: 27%
0.00095
Низкий
6.5 Medium
CVSS3
3.3 Low
CVSS2
Дефекты
CWE-200