PT-2018-13453 · Hangzhou Luoping · Hangzhou Luoping Smart Locker

Ant0Inet

+1

·

Published

2018-09-14

·

Updated

2019-10-03

·

CVE-2018-16242

CVSS v3.1

5.3

Medium

VectorAV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Hangzhou Luoping Smart Locker (affected versions not specified)
Description The issue concerns a predictable nonce used in the locking protocol of Hangzhou Luoping Smart Locker, which is utilized by oBike to lock bicycles. This predictability allows attackers to bypass the locking mechanism by using Bluetooth Low Energy (BLE) to replay ciphertext.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-16242

Affected Products

Hangzhou Luoping Smart Locker