PT-2017-7917 · Pebble · Pebble Smartwatch

Published

2017-11-28

·

Updated

2017-12-20

·

CVE-2016-10702

CVSS v3.1

6.1

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Pebble Smartwatch devices versions through 4.3
Description The issue concerns the mishandling of UUID storage, allowing attackers to read an arbitrary application's flash storage and access an arbitrary application's JavaScript instance. This can be achieved by modifying a UUID value within the header of a crafted application binary.
Recommendations For versions through 4.3, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-10702

Affected Products

Pebble Smartwatch