PT-2022-23866 · Chipolo · Chipolo One Bluetooth Tracker+1

·

CVE-2022-37193

·

Published

2022-09-27

·

Updated

2022-10-03

CVSS v3.1

7.4

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Chipolo ONE Bluetooth tracker (2020) version 4.13.0 Chipolo iOS app version 4.13.0
Description The issue concerns Incorrect Access Control, allowing access revocation evasion attacks. Once a malicious sharee obtains access credentials, Chipolo devices can be affected.
Recommendations For Chipolo ONE Bluetooth tracker (2020) version 4.13.0, update the Chipolo iOS app to a version that addresses the access control issue. For Chipolo iOS app version 4.13.0, consider restricting access to sensitive features until a patch is available.

Fix

Insufficiently Protected Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-37193

Affected Products

Chipolo One Bluetooth Tracker
Chipolo Ios App