PT-2023-24957 · Showmojo+1 · Showmojo Mojobox Digital Lockbox+1
Lockpickinglawyer
·
Published
2023-07-20
·
Updated
2023-07-28
·
CVE-2023-34625
CVSS v3.1
8.1
High
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
ShowMojo MojoBox Digital Lockbox version 1.4
Description
The implementation of the lock opening mechanism via Bluetooth Low Energy (BLE) is vulnerable to replay attacks. A malicious user can intercept BLE requests and replicate them to open the lock at any time. Alternatively, an attacker with physical access to the device on which the Android app is installed can obtain the latest BLE messages via the app logs and use them for opening the lock.
Recommendations
For ShowMojo MojoBox Digital Lockbox version 1.4, consider disabling the BLE lock opening mechanism until a patch is available. Restrict access to the app logs to minimize the risk of exploitation. Avoid using the Android app to open the lock until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Android
Showmojo Mojobox Digital Lockbox