PT-2024-15174 · Kontrol+2 · Kontrol+3

Idan Strovinsky

+2

·

Published

2024-03-07

·

Updated

2024-08-02

·

CVE-2023-7006

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Sciener firmware (affected versions not specified)
Description The issue concerns the unlockKey character in locks using Sciener firmware, which can be compromised through brute force attacks by sending repeated challenge requests. This affects the integrity of the locks. The firmware is used in electronic locks, such as Kontrol and Elock locks, and works with the TTLock app.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Related Identifiers

CVE-2023-7006

Affected Products

Elock
Kontrol
Sciener Firmware
Ttlock App