PT-2024-26997 · Elinksmart · Elinksmart Hidden Smart Cabinet Lock

Sebastian Auwärter

·

Published

2024-07-15

·

Updated

2024-08-01

·

CVE-2024-36438

CVSS v3.1

7.3

High

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
Name of the Vulnerable Software and Affected Versions eLinkSmart Hidden Smart Cabinet Lock (affected versions not specified)
Description The issue is related to incorrect access control, where the system fails to perform an authorization check. This can lead to card duplication and other attacks.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Improper Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-36438

Affected Products

Elinksmart Hidden Smart Cabinet Lock