ZeroHour

CVE-2021-40526

CVSS 3.1
5.3 medium
EPSS
<1%p60
Published
()
Modified
Description

Incorrect calculation of buffer size vulnerability in Peleton TTR01 up to and including PTV55G allows a remote attacker to trigger a Denial of Service attack through the GymKit daemon process by exploiting a heap overflow in the network server handling the Apple GymKit communication. This can lead to an Apple MFI device not being able to authenticate with the Peleton Bike

Vendors
onepeloton
Products
ttr01 firmware
Weakness
CWE-131
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

In the news

No ingested article mentions this CVE yet.