PT-2020-12676 · Tata · Tata Sonata Smart Sf Rush

Sayli Ambure

·

Published

2020-04-22

·

Updated

2021-07-21

·

CVE-2020-11539

CVSS v3.1

8.1

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Tata Sonata Smart SF Rush version 1.12
Description An issue has been identified where the smart band operates with no pairing, utilizing mode 0 Bluetooth LE security level. This results in unencrypted data transmission over the air. Furthermore, the data sent to the smart band lacks authentication or signature verification, allowing any attacker to control a parameter of the device.
Recommendations For Tata Sonata Smart SF Rush version 1.12, consider disabling Bluetooth connectivity until a patch or secure pairing mechanism is implemented to prevent unauthorized control of the device. Restrict access to the device's parameters to minimize the risk of exploitation. Avoid using the device until the issue is resolved with proper encryption and authentication measures. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Cleartext Transmission of Sensitive Information

Improper Verification of Cryptographic Signature

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-11539

Affected Products

Tata Sonata Smart Sf Rush