PT-2019-14871 · Nulock · Nulock
Published
2019-09-27
·
Updated
2019-10-04
·
CVE-2019-16924
CVSS v3.1
8.8
High
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Nulock application version 1.5.0
Description
The issue concerns the Nulock application sending a cleartext password over Bluetooth. This allows remote attackers, after sniffing the network, to take control of the lock.
Recommendations
For Nulock application version 1.5.0, consider disabling Bluetooth connectivity until a patch is available to prevent cleartext password transmission.
Exploit
Fix
Cleartext Transmission of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nulock