PT-2024-15172 · Sciener · Sciener Firmware

Idan Strovinsky

+2

·

Published

2024-03-07

·

Updated

2024-08-26

·

CVE-2023-7004

CVSS v3.1

6.5

Medium

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions TTLock App (affected versions not specified)
Description The issue arises from the TTLock App's failure to properly verify the device it is communicating with, allowing a device that spoofs the MAC address of a lock to connect and compromise the lock's integrity. This affects electronic locks that utilize firmware provided by Sciener, which works in tandem with the TTLock app.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

CVE-2023-7004

Affected Products

Sciener Firmware