PT-2018-18867 · Brilliantts · Brilliantts Fuze Card
Mpeg4Codec
·
Published
2018-04-04
·
Updated
2023-08-31
·
CVE-2018-9119
CVSS v3.1
6.1
Medium
| Vector | AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
BrilliantTS FUZE card (MCU firmware 0.1.73, BLE firmware 0.7.4)
Description
The issue allows an attacker with physical access to unlock the card, extract credit card numbers, and tamper with data on the card via Bluetooth, as no authentication is required. This has been demonstrated using gatttool.
Recommendations
For BrilliantTS FUZE card with MCU firmware 0.1.73 and BLE firmware 0.7.4, consider implementing authentication for Bluetooth connections to prevent unauthorized access until a patch is available. Restrict physical access to the card to minimize the risk of exploitation.
Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Brilliantts Fuze Card