Incorrect Session Management and Credential Re-use in the...
High severity
Unreviewed
Published
Dec 5, 2023
to the GitHub Advisory Database
•
Updated Jan 16, 2024
Description
Published by the National Vulnerability Database
Dec 5, 2023
Published to the GitHub Advisory Database
Dec 5, 2023
Last updated
Jan 16, 2024
Incorrect Session Management and Credential Re-use in the Bluetooth LE stack of the Ultraloq UL3 2nd Gen Smart Lock Firmware 02.27.0012 allows an attacker to sniff the unlock code and unlock the device whilst within Bluetooth range.
References