PT-2022-23866 · Chipolo · Chipolo One Bluetooth Tracker+1

Jiale Guan

+3

·

Published

2022-09-27

·

Updated

2022-10-03

·

CVE-2022-37193

CVSS v3.1

7.4

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Chipolo ONE Bluetooth tracker (2020) version 4.13.0 Chipolo iOS app version 4.13.0
Description The issue concerns Incorrect Access Control, allowing access revocation evasion attacks. Once a malicious sharee obtains access credentials, Chipolo devices can be affected.
Recommendations For Chipolo ONE Bluetooth tracker (2020) version 4.13.0, update the Chipolo iOS app to a version that addresses the access control issue. For Chipolo iOS app version 4.13.0, consider restricting access to sensitive features until a patch is available.

Fix

Insufficiently Protected Credentials

Weakness Enumeration

Related Identifiers

CVE-2022-37193

Affected Products

Chipolo One Bluetooth Tracker
Chipolo Ios App