PT-2020-20282 · Oklok · Oklok Mobile Companion App+1

Published

2020-05-04

·

Updated

2021-07-21

·

CVE-2020-8792

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions OKLOK mobile companion app version 3.1.1 Fingerprint Bluetooth Padlock FB50 version 2.3
Description The mobile app has an information-exposure issue. When attempting to add an already-bound lock by its barcode, the app reveals the email address of the account to which the lock is bound, as well as the name of the lock. The barcode strings follow a predictable pattern, making it easy to guess valid inputs. As a result, correctly guessed valid barcode inputs entered through the app interface can disclose arbitrary users' email addresses and lock names.
Recommendations For OKLOK mobile companion app version 3.1.1, consider implementing a more secure barcode generation mechanism to prevent predictable patterns. For Fingerprint Bluetooth Padlock FB50 version 2.3, restrict access to the lock's barcode input feature until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use of Insufficiently Random Values

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-8792

Affected Products

Fingerprint Bluetooth Padlock Fb50
Oklok Mobile Companion App