PT-2024-18723 · Unknown · Auto Hotspot

Published

2024-02-05

·

Updated

2024-02-14

·

CVE-2024-20816

CVSS v3.1

8.0

High

VectorAV:A/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions Auto Hotspot versions prior to SMR Feb-2024 Release 1
Description The issue is related to an improper authentication vulnerability in the onCharacteristicWriteRequest function. This allows adjacent attackers to connect to a victim's mobile hotspot without the user's awareness.
Recommendations For versions prior to SMR Feb-2024 Release 1, update to SMR Feb-2024 Release 1 or later to resolve the issue. As a temporary workaround, consider restricting access to the onCharacteristicWriteRequest function until a patch is available.

Fix

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2024-20816

Affected Products

Auto Hotspot