CVE-2022-46480

Incorrect Session Management and Credential Re-use in the Bluetooth LE stack of the Ultraloq UL3 2nd Gen Smart Lock Firmware 02.27.0012 allows an attacker to sniff the unlock code and unlock the device whilst within Bluetooth range.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:u-tec:ultraloq_ul3_bt_firmware:02.27.0012:*:*:*:*:*:*:*
cpe:2.3:h:u-tec:ultraloq_ul3_bt:2nd_gen:*:*:*:*:*:*:*

History

16 Jan 2024, 02:15

Type Values Removed Values Added
References
  • () https://arxiv.org/abs/2312.00021 -

08 Dec 2023, 17:27

Type Values Removed Values Added
CWE CWE-294
CWE-384
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.1
CPE cpe:2.3:h:u-tec:ultraloq_ul3_bt:2nd_gen:*:*:*:*:*:*:*
cpe:2.3:o:u-tec:ultraloq_ul3_bt_firmware:02.27.0012:*:*:*:*:*:*:*
First Time U-tec
U-tec ultraloq Ul3 Bt Firmware
U-tec ultraloq Ul3 Bt
References () https://www.researchgate.net/publication/375759408_Technical_Report_-_CVE-2022-46480_CVE-2023-26941_CVE-2023-26942_and_CVE-2023-26943#fullTextFileContent - () https://www.researchgate.net/publication/375759408_Technical_Report_-_CVE-2022-46480_CVE-2023-26941_CVE-2023-26942_and_CVE-2023-26943#fullTextFileContent - Exploit, Technical Description, Third Party Advisory

05 Dec 2023, 00:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-12-05 00:15

Updated : 2024-01-16 02:15


NVD link : CVE-2022-46480

Mitre link : CVE-2022-46480

CVE.ORG link : CVE-2022-46480


JSON object : View

Products Affected

u-tec

  • ultraloq_ul3_bt
  • ultraloq_ul3_bt_firmware
CWE
CWE-294

Authentication Bypass by Capture-replay

CWE-384

Session Fixation