Incorrect Session Management and Credential Re-use in the Bluetooth LE stack of the Ultraloq UL3 2nd Gen Smart Lock Firmware 02.27.0012 allows an attacker to sniff the unlock code and unlock the device whilst within Bluetooth range.
References
Link | Resource |
---|---|
https://arxiv.org/abs/2312.00021 | |
https://www.researchgate.net/publication/375759408_Technical_Report_-_CVE-2022-46480_CVE-2023-26941_CVE-2023-26942_and_CVE-2023-26943#fullTextFileContent | Exploit Technical Description Third Party Advisory |
https://arxiv.org/abs/2312.00021 | |
https://www.researchgate.net/publication/375759408_Technical_Report_-_CVE-2022-46480_CVE-2023-26941_CVE-2023-26942_and_CVE-2023-26943#fullTextFileContent | Exploit Technical Description Third Party Advisory |
Configurations
Configuration 1 (hide)
AND |
|
History
21 Nov 2024, 07:30
Type | Values Removed | Values Added |
---|---|---|
References | () https://arxiv.org/abs/2312.00021 - | |
References | () https://www.researchgate.net/publication/375759408_Technical_Report_-_CVE-2022-46480_CVE-2023-26941_CVE-2023-26942_and_CVE-2023-26943#fullTextFileContent - Exploit, Technical Description, Third Party Advisory |
16 Jan 2024, 02:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
08 Dec 2023, 17:27
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-294 CWE-384 |
|
CPE | cpe:2.3:o:u-tec:ultraloq_ul3_bt_firmware:02.27.0012:*:*:*:*:*:*:* cpe:2.3:h:u-tec:ultraloq_ul3_bt:2nd_gen:*:*:*:*:*:*:* |
|
First Time |
U-tec ultraloq Ul3 Bt Firmware
U-tec U-tec ultraloq Ul3 Bt |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.1 |
References | () https://www.researchgate.net/publication/375759408_Technical_Report_-_CVE-2022-46480_CVE-2023-26941_CVE-2023-26942_and_CVE-2023-26943#fullTextFileContent - Exploit, Technical Description, Third Party Advisory |
05 Dec 2023, 00:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-12-05 00:15
Updated : 2024-11-21 07:30
NVD link : CVE-2022-46480
Mitre link : CVE-2022-46480
CVE.ORG link : CVE-2022-46480
JSON object : View
Products Affected
u-tec
- ultraloq_ul3_bt
- ultraloq_ul3_bt_firmware