PT-2024-15174 · Kontrol+2 · Kontrol+3
Idan Strovinsky
+2
·
Published
2024-03-07
·
Updated
2024-08-02
·
CVE-2023-7006
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Sciener firmware (affected versions not specified)
Description
The issue concerns the unlockKey character in locks using Sciener firmware, which can be compromised through brute force attacks by sending repeated challenge requests. This affects the integrity of the locks. The firmware is used in electronic locks, such as Kontrol and Elock locks, and works with the TTLock app.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Elock
Kontrol
Sciener Firmware
Ttlock App