PT-2021-7218 · Owl · Owl Labs Meeting Owl
Published
2021-10-22
·
Updated
2023-09-18
·
CVE-2022-31462
CVSS v3.1
9.3
Critical
| Vector | AC:L/AV:A/A:N/C:H/I:H/PR:N/S:C/UI:N |
Name of the Vulnerable Software and Affected Versions
Owl Labs Meeting Owl version 5.2.0.15
Description
The issue is related to the implementation of Bluetooth Low Energy (BLE) technology in the microprogram of the Meeting Owl Pro camera for video conferencing. It involves the use of a hardcoded password for account credentials, which is derived from the device's serial number. This can be exploited by an attacker to bypass existing security restrictions using a brute force attack. The backdoor password can be found in Bluetooth broadcast data, allowing attackers to control the device.
Recommendations
For version 5.2.0.15, consider disabling the Bluetooth functionality until a patch is available to prevent exploitation of the hardcoded password.
As a temporary workaround, restrict access to the device's serial number to minimize the risk of the backdoor password being derived.
Avoid using the device for sensitive video conferences until the issue is resolved.
Exploit
Fix
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Owl Labs Meeting Owl