TROYANOSYVIRUS
Back to CVEs

CVE-2022-46480

HIGH
8.1

Description

Incorrect Session Management and Credential Re-use in the Bluetooth LE stack of the Ultraloq UL3 2nd Gen Smart Lock Firmware 02.27.0012 allows an attacker to sniff the unlock code and unlock the device whilst within Bluetooth range.

CVE Details

CVSS v3.1 Score8.1
SeverityHIGH
CVSS VectorCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Attack VectorADJACENT_NETWORK
ComplexityLOW
Privileges RequiredNONE
User InteractionNONE
Published12/5/2023
Last Modified11/21/2024
Sourcenvd
Honeypot Sightings0

Affected Products

u-tec:ultraloq_ul3_btu-tec:ultraloq_ul3_bt_firmware

Weaknesses (CWE)

CWE-294CWE-384

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.