PT-2021-7218 · Owl · Owl Labs Meeting Owl

Published

2021-10-22

·

Updated

2023-09-18

·

CVE-2022-31462

CVSS v3.1

9.3

Critical

VectorAC:L/AV:A/A:N/C:H/I:H/PR:N/S:C/UI:N
Name of the Vulnerable Software and Affected Versions Owl Labs Meeting Owl version 5.2.0.15
Description The issue is related to the implementation of Bluetooth Low Energy (BLE) technology in the microprogram of the Meeting Owl Pro camera for video conferencing. It involves the use of a hardcoded password for account credentials, which is derived from the device's serial number. This can be exploited by an attacker to bypass existing security restrictions using a brute force attack. The backdoor password can be found in Bluetooth broadcast data, allowing attackers to control the device.
Recommendations For version 5.2.0.15, consider disabling the Bluetooth functionality until a patch is available to prevent exploitation of the hardcoded password. As a temporary workaround, restrict access to the device's serial number to minimize the risk of the backdoor password being derived. Avoid using the device for sensitive video conferences until the issue is resolved.

Exploit

Fix

Using Hardcoded Credentials

Weakness Enumeration

Related Identifiers

BDU:2022-03880
CVE-2022-31462

Affected Products

Owl Labs Meeting Owl