Sciener kayıtları
sciener üreticisine ait 6 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-311 Missing Encryption of Sensitive Data1
- CWE-323 Reusing a Nonce, Key Pair in Encryption1
- CWE-324 Use of a Key Past its Expiration Date1
- CWE-494 Download of Code Without Integrity Check1
- CWE-799 Improper Control of Interaction Frequency1
- CWE-940 Improper Verification of Source of a Communication Channel1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWESaldırı profili
Tüm kayıtlar
6 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2023-7017İstismar yok | Sciener locks' firmware update mechanism do not authenticate or validate firmware updates if passed to the lock through the Bluetooth Low Ensciener · kontrol lux · CWE-494 | Kritik9,8 | — | %0,3 | 15 Mar 2024 |
36İzleyin | CVE-2023-7006İstismar yok | The unlockKey character in a lock using Sciener firmware can be brute forced through repeated challenge requests, compromising the locks intsciener · kontrol lux · CWE-799 | Kritik9,1 | — | %0,5 | 15 Mar 2024 |
32İzleyin | CVE-2023-7009İstismar yok | Some Sciener-based locks support plaintext message processing over Bluetooth Low Energy, allowing unencrypted malicious commands to be passesciener · kontrol lux · CWE-311 | Yüksek8,2 | — | %0,2 | 15 Mar 2024 |
30İzleyin | CVE-2023-6960İstismar yok | TTLock App virtual keys and settings are only deleted client side, and if preserved, can access the lock after intended deletion.sciener · ttlock app · CWE-324 | Yüksek7,5 | — | %0,3 | 15 Mar 2024 |
27İzleyin | CVE-2023-7003İstismar yok | The AES key utilized in the pairing process between a lock using Sciener firmware and a wireless keypad is not unique, and can be reused to sciener · kontrol lux · CWE-323 | Orta6,8 | — | %0,3 | 15 Mar 2024 |
26İzleyin | CVE-2023-7004İstismar yok | The TTLock App does not employ proper verification procedures to ensure that it is communicating with the expected device, allowing for connsciener · ttlock app · CWE-940 | Orta6,5 | — | %0,2 | 15 Mar 2024 |
- CVE-2023-701739İzleyin
Sciener locks' firmware update mechanism do not authenticate or validate firmware updates if passed to the lock through the Bluetooth Low En
KritikCVSS 9,8İstismar yokEPSS %0sciener · kontrol lux15 Mar 2024
- CVE-2023-700636İzleyin
The unlockKey character in a lock using Sciener firmware can be brute forced through repeated challenge requests, compromising the locks int
KritikCVSS 9,1İstismar yokEPSS %1sciener · kontrol lux15 Mar 2024
- CVE-2023-700932İzleyin
Some Sciener-based locks support plaintext message processing over Bluetooth Low Energy, allowing unencrypted malicious commands to be passe
YüksekCVSS 8,2İstismar yokEPSS %0sciener · kontrol lux15 Mar 2024
- CVE-2023-696030İzleyin
TTLock App virtual keys and settings are only deleted client side, and if preserved, can access the lock after intended deletion.
YüksekCVSS 7,5İstismar yokEPSS %0sciener · ttlock app15 Mar 2024
- CVE-2023-700327İzleyin
The AES key utilized in the pairing process between a lock using Sciener firmware and a wireless keypad is not unique, and can be reused to
OrtaCVSS 6,8İstismar yokEPSS %0sciener · kontrol lux15 Mar 2024
- CVE-2023-700426İzleyin
The TTLock App does not employ proper verification procedures to ensure that it is communicating with the expected device, allowing for conn
OrtaCVSS 6,5İstismar yokEPSS %0sciener · ttlock app15 Mar 2024