ZeroHour

CVE-2018-16242

PoC
CVSS 3.0
5.3 medium
EPSS
<1%p50
Published
()
Modified
Description

oBike relies on Hangzhou Luoping Smart Locker to lock bicycles, which allows attackers to bypass the locking mechanism by using Bluetooth Low Energy (BLE) to replay ciphertext based on a predictable nonce used in the locking protocol.

Vendors
o.bike
Products
smart locker firmware, obike-stationless bike sharing
Weakness
CWE-294
Vector
CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.