PT-2018-18867 · Brilliantts · Brilliantts Fuze Card

Mpeg4Codec

·

Published

2018-04-04

·

Updated

2023-08-31

·

CVE-2018-9119

CVSS v3.1

6.1

Medium

VectorAV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions BrilliantTS FUZE card (MCU firmware 0.1.73, BLE firmware 0.7.4)
Description The issue allows an attacker with physical access to unlock the card, extract credit card numbers, and tamper with data on the card via Bluetooth, as no authentication is required. This has been demonstrated using gatttool.
Recommendations For BrilliantTS FUZE card with MCU firmware 0.1.73 and BLE firmware 0.7.4, consider implementing authentication for Bluetooth connections to prevent unauthorized access until a patch is available. Restrict physical access to the card to minimize the risk of exploitation.

Fix

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2018-9119

Affected Products

Brilliantts Fuze Card