PT-2017-7917 · Pebble · Pebble Smartwatch
Publicado
2017-11-28
·
Atualizado
2017-12-20
·
CVE-2016-10702
CVSS v3.1
6.1
Média
| Vetor | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Pebble Smartwatch devices versions through 4.3
Description
The issue concerns the mishandling of UUID storage, allowing attackers to read an arbitrary application's flash storage and access an arbitrary application's JavaScript instance. This can be achieved by modifying a UUID value within the header of a crafted application binary.
Recommendations
For versions through 4.3, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Pebble Smartwatch