Записи Sciener
6 опубликованных записей вендора sciener.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-311 Missing Encryption of Sensitive Data1
- CWE-323 Reusing a Nonce, Key Pair in Encryption1
- CWE-324 Use of a Key Past its Expiration Date1
- CWE-494 Download of Code Without Integrity Check1
- CWE-799 Improper Control of Interaction Frequency1
- CWE-940 Improper Verification of Source of a Communication Channel1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEПрофиль атаки
Все записи
6 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
39Наблюдать | CVE-2023-7017Эксплойта нет | Sciener locks' firmware update mechanism do not authenticate or validate firmware updates if passed to the lock through the Bluetooth Low Ensciener · kontrol lux · CWE-494 | Критическая9,8 | — | 0,3 % | 15 мар. 2024 г. |
36Наблюдать | CVE-2023-7006Эксплойта нет | The unlockKey character in a lock using Sciener firmware can be brute forced through repeated challenge requests, compromising the locks intsciener · kontrol lux · CWE-799 | Критическая9,1 | — | 0,5 % | 15 мар. 2024 г. |
32Наблюдать | CVE-2023-7009Эксплойта нет | Some Sciener-based locks support plaintext message processing over Bluetooth Low Energy, allowing unencrypted malicious commands to be passesciener · kontrol lux · CWE-311 | Высокая8,2 | — | 0,2 % | 15 мар. 2024 г. |
30Наблюдать | CVE-2023-6960Эксплойта нет | TTLock App virtual keys and settings are only deleted client side, and if preserved, can access the lock after intended deletion.sciener · ttlock app · CWE-324 | Высокая7,5 | — | 0,3 % | 15 мар. 2024 г. |
27Наблюдать | CVE-2023-7003Эксплойта нет | The AES key utilized in the pairing process between a lock using Sciener firmware and a wireless keypad is not unique, and can be reused to sciener · kontrol lux · CWE-323 | Средняя6,8 | — | 0,3 % | 15 мар. 2024 г. |
26Наблюдать | CVE-2023-7004Эксплойта нет | The TTLock App does not employ proper verification procedures to ensure that it is communicating with the expected device, allowing for connsciener · ttlock app · CWE-940 | Средняя6,5 | — | 0,2 % | 15 мар. 2024 г. |
- CVE-2023-701739Наблюдать
Sciener locks' firmware update mechanism do not authenticate or validate firmware updates if passed to the lock through the Bluetooth Low En
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %sciener · kontrol lux15 мар. 2024 г.
- CVE-2023-700636Наблюдать
The unlockKey character in a lock using Sciener firmware can be brute forced through repeated challenge requests, compromising the locks int
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %sciener · kontrol lux15 мар. 2024 г.
- CVE-2023-700932Наблюдать
Some Sciener-based locks support plaintext message processing over Bluetooth Low Energy, allowing unencrypted malicious commands to be passe
ВысокаяCVSS 8,2Эксплойта нетEPSS 0 %sciener · kontrol lux15 мар. 2024 г.
- CVE-2023-696030Наблюдать
TTLock App virtual keys and settings are only deleted client side, and if preserved, can access the lock after intended deletion.
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %sciener · ttlock app15 мар. 2024 г.
- CVE-2023-700327Наблюдать
The AES key utilized in the pairing process between a lock using Sciener firmware and a wireless keypad is not unique, and can be reused to
СредняяCVSS 6,8Эксплойта нетEPSS 0 %sciener · kontrol lux15 мар. 2024 г.
- CVE-2023-700426Наблюдать
The TTLock App does not employ proper verification procedures to ensure that it is communicating with the expected device, allowing for conn
СредняяCVSS 6,5Эксплойта нетEPSS 0 %sciener · ttlock app15 мар. 2024 г.