PT-2017-14778 · Vaultek · Vaultek Gun Safe Vt20I

Publicado

2017-12-07

·

Atualizado

2017-12-22

·

CVE-2017-17435

CVSS v2.0

8.3

Alta

VetorAV:A/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Vaultek Gun Safe VT20i products
Description An issue in the Vaultek Gun Safe VT20i products allows an attacker to remotely unlock any safe without a valid PIN code. The safe does not verify the PIN code supplied in the authorization request, enabling an attacker to obtain authorization using any value. The attacker can exploit this by writing a Bluetooth Low Energy (BLE) characteristic to enable notifications, sending a crafted getAuthor packet to obtain a temporary key, and then sending an unlock packet with that temporary key. This results in the safe opening without verifying the PIN or other credentials.
Recommendations For Vaultek Gun Safe VT20i products, as a temporary workaround, consider disabling the Bluetooth Low Energy (BLE) functionality until a patch is available. Restrict access to the safe's BLE advertisement to minimize the risk of exploitation. Avoid using the phone application for authorization until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-17435

Produtos afetados

Vaultek Gun Safe Vt20I