PT-2023-24957 · Showmojo+1 · Showmojo Mojobox Digital Lockbox+1

Lockpickinglawyer

·

Published

2023-07-20

·

Updated

2023-07-28

·

CVE-2023-34625

CVSS v3.1

8.1

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions ShowMojo MojoBox Digital Lockbox version 1.4
Description The implementation of the lock opening mechanism via Bluetooth Low Energy (BLE) is vulnerable to replay attacks. A malicious user can intercept BLE requests and replicate them to open the lock at any time. Alternatively, an attacker with physical access to the device on which the Android app is installed can obtain the latest BLE messages via the app logs and use them for opening the lock.
Recommendations For ShowMojo MojoBox Digital Lockbox version 1.4, consider disabling the BLE lock opening mechanism until a patch is available. Restrict access to the app logs to minimize the risk of exploitation. Avoid using the Android app to open the lock until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-34625

Affected Products

Android
Showmojo Mojobox Digital Lockbox