Sciener locks' firmware update... CVE-2023-7017

- AV AC AU C I A
发布: 2024-03-15
修订: 2024-08-28

Sciener locks' firmware update mechanism do not authenticate or validate firmware updates if passed to the lock through the Bluetooth Low Energy service. A challenge request can be sent to the lock with a command to prepare for an update, rather than an unlock request, allowing an attacker to compromise the device.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息