PT-2022-22939 · Nautilus · Nautilus T616+1

Published

2022-07-12

·

Updated

2022-07-25

·

CVE-2022-35648

CVSS v3.1

2.6

Low

VectorAC:L/AV:P/A:L/C:N/I:N/PR:N/S:C/UI:N
Name of the Vulnerable Software and Affected Versions Nautilus T616 versions 100672PRO21140001 through 100672PRO21171980 Nautilus T618 versions 100647PRO21130111 through 100647PRO21183960
Description The issue allows physically proximate attackers to cause a denial of service, potentially leading to a fall, by connecting the power cord to a 120V circuit. This may cause the treadmill to self-start at an inopportune time.
Recommendations For Nautilus T616 versions 100672PRO21140001 through 100672PRO21171980, update the software to a version released after 2022-06-09. For Nautilus T618 versions 100647PRO21130111 through 100647PRO21183960, update the software to a version released after 2022-06-09. As a temporary workaround, consider disconnecting the power cord when not in use to prevent self-starting.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2022-35648

Affected Products

Nautilus T616
Nautilus T618