PT-2019-15236 · Yale · Yale Bluetooth Key Application+1

Light

+1

·

Publicado

2019-10-16

·

Atualizado

2019-10-18

·

CVE-2019-17627

CVSS v2.0

3.3

Baixa

VetorAV:A/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Yale Bluetooth Key application (affected versions not specified) Yale ZEN-R lock (affected versions not specified)
Description The issue allows unauthorized unlock actions by sniffing Bluetooth Low Energy (BLE) traffic during one authorized unlock action, and then calculating the authentication key via simple computations on the hex digits of a valid authentication request.
Recommendations For the Yale Bluetooth Key application, at the moment, there is no information about a newer version that contains a fix for this vulnerability. For the Yale ZEN-R lock, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-17627

Produtos afetados

Yale Bluetooth Key Application
Yale Zen-R Lock