ZeroHour

CVE-2020-8790

PoC
CVSS 3.1
9.8 critical
EPSS
2%p75
Published
()
Modified
Description

The OKLOK (3.1.1) mobile companion app for Fingerprint Bluetooth Padlock FB50 (2.3) has weak password requirements combined with improper restriction of excessive authentication attempts, which could allow a remote attacker to discover user credentials and obtain access via a brute force attack.

Vendors
oklok project
Products
oklok
Weakness
CWE-307, CWE-521
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.