PT-2024-11571 · Nuki · Nuki Smart Lock 3.0+1

Published

2024-05-09

·

Updated

2024-08-14

·

CVE-2022-32507

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Nuki Smart Lock 3.0 versions 3.0 through 3.3.4 Nuki Smart Lock 2.0 versions 2.0 through 2.12.3
Description An issue was discovered on certain Nuki Home Solutions devices, where some BLE commands could be called from unprivileged accounts, despite being designed for privileged accounts only. This is due to the lack of access controls for BLE commands across different accounts.
Recommendations For Nuki Smart Lock 3.0 versions 3.0 through 3.3.4, update to version 3.3.5 or later. For Nuki Smart Lock 2.0 versions 2.0 through 2.12.3, update to version 2.12.4 or later.

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2022-32507

Affected Products

Nuki Smart Lock 2.0
Nuki Smart Lock 3.0