PT-2022-22939 · Nautilus · Nautilus T616+1
Published
2022-07-12
·
Updated
2022-07-25
·
CVE-2022-35648
CVSS v3.1
2.6
Low
| Vector | AC:L/AV:P/A:L/C:N/I:N/PR:N/S:C/UI:N |
Name of the Vulnerable Software and Affected Versions
Nautilus T616 versions 100672PRO21140001 through 100672PRO21171980
Nautilus T618 versions 100647PRO21130111 through 100647PRO21183960
Description
The issue allows physically proximate attackers to cause a denial of service, potentially leading to a fall, by connecting the power cord to a 120V circuit. This may cause the treadmill to self-start at an inopportune time.
Recommendations
For Nautilus T616 versions 100672PRO21140001 through 100672PRO21171980, update the software to a version released after 2022-06-09.
For Nautilus T618 versions 100647PRO21130111 through 100647PRO21183960, update the software to a version released after 2022-06-09.
As a temporary workaround, consider disconnecting the power cord when not in use to prevent self-starting.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Nautilus T616
Nautilus T618