PT-2024-15176 · Unknown · Sciener-Based Locks

Published

2024-03-15

·

Updated

2024-08-26

·

CVE-2023-7009

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
Name of the Vulnerable Software and Affected Versions Sciener-based locks (affected versions not specified)
Description The issue allows unencrypted malicious commands to be passed to the lock over Bluetooth Low Energy, as some Sciener-based locks support plaintext message processing. These malicious commands, less than 16 bytes in length, are processed by the lock as if they were encrypted communications, potentially compromising the lock's integrity.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Related Identifiers

CVE-2023-7009

Affected Products

Sciener-Based Locks