CVE-2023-7017 Information
Mar 16, 2024
cve
Description
Sciener locks’ firmware update mechanism do not authenticate or validate firmware updates if passed to the lock through the Bluetooth Low Energy service. A challenge request can be sent to the lock with a command to prepare for an update rather than an unlock request allowing an attacker to compromise the device.
Reference
https://alephsecurity.com/2024/03/07/kontrol-lux-lock-2/
Share on: