Sciener records
6 published records for vendor sciener.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-311 Missing Encryption of Sensitive Data1
- CWE-323 Reusing a Nonce, Key Pair in Encryption1
- CWE-324 Use of a Key Past its Expiration Date1
- CWE-494 Download of Code Without Integrity Check1
- CWE-799 Improper Control of Interaction Frequency1
- CWE-940 Improper Verification of Source of a Communication Channel1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
6 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2023-7017No exploit | Sciener locks' firmware update mechanism do not authenticate or validate firmware updates if passed to the lock through the Bluetooth Low Ensciener · kontrol lux · CWE-494 | Critical9.8 | — | 0.3% | Mar 15, 2024 |
36Monitor | CVE-2023-7006No exploit | The unlockKey character in a lock using Sciener firmware can be brute forced through repeated challenge requests, compromising the locks intsciener · kontrol lux · CWE-799 | Critical9.1 | — | 0.5% | Mar 15, 2024 |
32Monitor | CVE-2023-7009No exploit | Some Sciener-based locks support plaintext message processing over Bluetooth Low Energy, allowing unencrypted malicious commands to be passesciener · kontrol lux · CWE-311 | High8.2 | — | 0.2% | Mar 15, 2024 |
30Monitor | CVE-2023-6960No exploit | TTLock App virtual keys and settings are only deleted client side, and if preserved, can access the lock after intended deletion.sciener · ttlock app · CWE-324 | High7.5 | — | 0.3% | Mar 15, 2024 |
27Monitor | CVE-2023-7003No exploit | The AES key utilized in the pairing process between a lock using Sciener firmware and a wireless keypad is not unique, and can be reused to sciener · kontrol lux · CWE-323 | Medium6.8 | — | 0.3% | Mar 15, 2024 |
26Monitor | CVE-2023-7004No exploit | The TTLock App does not employ proper verification procedures to ensure that it is communicating with the expected device, allowing for connsciener · ttlock app · CWE-940 | Medium6.5 | — | 0.2% | Mar 15, 2024 |
- CVE-2023-701739Monitor
Sciener locks' firmware update mechanism do not authenticate or validate firmware updates if passed to the lock through the Bluetooth Low En
CriticalCVSS 9.8No exploitEPSS 0%sciener · kontrol luxMar 15, 2024
- CVE-2023-700636Monitor
The unlockKey character in a lock using Sciener firmware can be brute forced through repeated challenge requests, compromising the locks int
CriticalCVSS 9.1No exploitEPSS 1%sciener · kontrol luxMar 15, 2024
- CVE-2023-700932Monitor
Some Sciener-based locks support plaintext message processing over Bluetooth Low Energy, allowing unencrypted malicious commands to be passe
HighCVSS 8.2No exploitEPSS 0%sciener · kontrol luxMar 15, 2024
- CVE-2023-696030Monitor
TTLock App virtual keys and settings are only deleted client side, and if preserved, can access the lock after intended deletion.
HighCVSS 7.5No exploitEPSS 0%sciener · ttlock appMar 15, 2024
- CVE-2023-700327Monitor
The AES key utilized in the pairing process between a lock using Sciener firmware and a wireless keypad is not unique, and can be reused to
MediumCVSS 6.8No exploitEPSS 0%sciener · kontrol luxMar 15, 2024
- CVE-2023-700426Monitor
The TTLock App does not employ proper verification procedures to ensure that it is communicating with the expected device, allowing for conn
MediumCVSS 6.5No exploitEPSS 0%sciener · ttlock appMar 15, 2024