PT-2024-11566 · Nuki Home Solutions · Nuki Bridge

Published

2024-05-09

·

Updated

2024-07-03

·

CVE-2022-32502

CVSS v3.1

6.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Nuki Bridge versions prior to 1.22.0 Nuki Bridge versions prior to 2.13.2
Description A buffer overflow issue was discovered in the HTTP service of certain Nuki Home Solutions devices, specifically in the encrypted token parsing logic. This issue allows for remote code execution.
Recommendations For Nuki Bridge versions prior to 1.22.0, update to version 1.22.0 or later. For Nuki Bridge versions prior to 2.13.2, update to version 2.13.2 or later.

Fix

Stack Overflow

Weakness Enumeration

Related Identifiers

CVE-2022-32502

Affected Products

Nuki Bridge