PT-2020-12676 · Tata · Tata Sonata Smart Sf Rush
Sayli Ambure
·
Published
2020-04-22
·
Updated
2021-07-21
·
CVE-2020-11539
CVSS v3.1
8.1
High
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Tata Sonata Smart SF Rush version 1.12
Description
An issue has been identified where the smart band operates with no pairing, utilizing mode 0 Bluetooth LE security level. This results in unencrypted data transmission over the air. Furthermore, the data sent to the smart band lacks authentication or signature verification, allowing any attacker to control a parameter of the device.
Recommendations
For Tata Sonata Smart SF Rush version 1.12, consider disabling Bluetooth connectivity until a patch or secure pairing mechanism is implemented to prevent unauthorized control of the device. Restrict access to the device's parameters to minimize the risk of exploitation. Avoid using the device until the issue is resolved with proper encryption and authentication measures. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Cleartext Transmission of Sensitive Information
Improper Verification of Cryptographic Signature
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Tata Sonata Smart Sf Rush