Описание
A lack of authentication and authorization mechanisms in the Bluetooth Low Energy (BLE) communication protocol of SRK Powertech Pvt Ltd Pebble Prism Ultra v2.9.2 allows attackers to reverse engineer the protocol and execute arbitrary commands on the device without establishing a connection. This is exploitable over Bluetooth Low Energy (BLE) proximity (Adjacent), requiring no physical contact with the device. Furthermore, the vulnerability is not limited to arbitrary commands but includes cleartext data interception and unauthenticated firmware hijacking via OTA services.
Ссылки
- ExploitThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2.5.8 (исключая)
Одновременно
cpe:2.3:o:pebblepower:pebble_prism_ultra_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:pebblepower:pebble_prism_ultra:-:*:*:*:*:*:*:*
EPSS
Процентиль: 12%
0.00041
Низкий
9.6 Critical
CVSS3
Дефекты
CWE-311
Связанные уязвимости
CVSS3: 9.6
debian
около 1 месяца назад
A lack of authentication and authorization mechanisms in the Bluetooth ...
EPSS
Процентиль: 12%
0.00041
Низкий
9.6 Critical
CVSS3
Дефекты
CWE-311