PT-2020-8191 · Syska · Syska Smart Bulb

Published

2020-02-10

·

Updated

2020-02-12

·

CVE-2017-18642

CVSS v3.1

6.5

Medium

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Syska Smart Bulb devices through 2017-08-06
Description: The issue allows for sniffing, reverse engineering, and replay attacks due to the reception of RGB parameters over cleartext Bluetooth Low Energy (BLE).
Recommendations: For Syska Smart Bulb devices through 2017-08-06, consider disabling Bluetooth Low Energy (BLE) connectivity until a secure method of parameter transmission is implemented. Restrict access to the BLE interface to minimize the risk of exploitation. Avoid using the RGB parameters in the affected BLE communication until the issue is resolved.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-18642

Affected Products

Syska Smart Bulb