Skip to content
Noroxi

Sciener records

6 published records for vendor sciener.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
0%
Median publish → KEV
No record has entered KEV

All records

6 records
  • CVE-2023-7017
    39Monitor

    Sciener locks' firmware update mechanism do not authenticate or validate firmware updates if passed to the lock through the Bluetooth Low En

    CriticalCVSS 9.8No exploitEPSS 0%

    sciener · kontrol luxMar 15, 2024

  • CVE-2023-7006
    36Monitor

    The unlockKey character in a lock using Sciener firmware can be brute forced through repeated challenge requests, compromising the locks int

    CriticalCVSS 9.1No exploitEPSS 1%

    sciener · kontrol luxMar 15, 2024

  • CVE-2023-7009
    32Monitor

    Some Sciener-based locks support plaintext message processing over Bluetooth Low Energy, allowing unencrypted malicious commands to be passe

    HighCVSS 8.2No exploitEPSS 0%

    sciener · kontrol luxMar 15, 2024

  • CVE-2023-6960
    30Monitor

    TTLock App virtual keys and settings are only deleted client side, and if preserved, can access the lock after intended deletion.

    HighCVSS 7.5No exploitEPSS 0%

    sciener · ttlock appMar 15, 2024

  • CVE-2023-7003
    27Monitor

    The AES key utilized in the pairing process between a lock using Sciener firmware and a wireless keypad is not unique, and can be reused to

    MediumCVSS 6.8No exploitEPSS 0%

    sciener · kontrol luxMar 15, 2024

  • CVE-2023-7004
    26Monitor

    The TTLock App does not employ proper verification procedures to ensure that it is communicating with the expected device, allowing for conn

    MediumCVSS 6.5No exploitEPSS 0%

    sciener · ttlock appMar 15, 2024