PT-2024-15180 · Unknown · Sciener Locks

Idan Strovinsky

+3

·

Published

2024-03-15

·

Updated

2024-08-28

·

CVE-2023-7017

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Sciener locks (affected versions not specified)
Description The firmware update mechanism of the locks does not authenticate or validate firmware updates when they are passed through the Bluetooth Low Energy service. An attacker can send a challenge request with a command to prepare for an update, rather than an unlock request, which allows the attacker to compromise the device.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Related Identifiers

CVE-2023-7017

Affected Products

Sciener Locks