PT-2024-11569 · Nuki · Nuki Smart Lock 3.0+1

Published

2024-05-09

·

Updated

2024-08-19

·

CVE-2022-32505

CVSS v3.1

7.1

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Nuki Smart Lock 3.0 versions 3.0 through 3.3.4 Nuki Smart Lock 2.0 versions 2.0 through 2.12.3
Description An issue was discovered on certain Nuki Home Solutions devices, where it is possible to send multiple BLE malformed packets to block some of the functionality and reboot the device.
Recommendations For Nuki Smart Lock 3.0 versions 3.0 through 3.3.4, update to version 3.3.5 or later. For Nuki Smart Lock 2.0 versions 2.0 through 2.12.3, update to version 2.12.4 or later.

Fix

Resource Exhaustion

Weakness Enumeration

Related Identifiers

CVE-2022-32505

Affected Products

Nuki Smart Lock 2.0
Nuki Smart Lock 3.0