ZeroHour

CVE-2022-46480

PoC
CVSS 3.1
8.1 high
EPSS
<1%p39
Published
()
Modified
Description

Incorrect Session Management and Credential Re-use in the Bluetooth LE stack of the Ultraloq UL3 2nd Gen Smart Lock Firmware 02.27.0012 allows an attacker to sniff the unlock code and unlock the device whilst within Bluetooth range.

Vendors
u-tec
Products
ultraloq ul3 bt firmware
Weakness
CWE-294, CWE-384
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.