PT-2020-8191 · Syska · Syska Smart Bulb
Published
2020-02-10
·
Updated
2020-02-12
·
CVE-2017-18642
CVSS v3.1
6.5
Medium
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Syska Smart Bulb devices through 2017-08-06
Description:
The issue allows for sniffing, reverse engineering, and replay attacks due to the reception of RGB parameters over cleartext Bluetooth Low Energy (BLE).
Recommendations:
For Syska Smart Bulb devices through 2017-08-06, consider disabling Bluetooth Low Energy (BLE) connectivity until a secure method of parameter transmission is implemented. Restrict access to the BLE interface to minimize the risk of exploitation. Avoid using the
RGB parameters in the affected BLE communication until the issue is resolved.Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Syska Smart Bulb