Vulnerability Description
Mimo Baby 2 devices do not use authentication or encryption for the Bluetooth Low Energy (BLE) communication from a Turtle to a Lilypad, which allows attackers to inject fake information about the position and temperature of a baby via a replay or spoofing attack.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mimobaby | Mimo Baby 2 Firmware | - |
| Mimobaby | Mimo Baby 2 | - |
Related Weaknesses (CWE)
References
- https://medium.com/%40victor_14768/mimo-baby-hack-ac7fa0ae3bfb
- https://medium.com/%40victor_14768/mimo-baby-hack-ac7fa0ae3bfb
FAQ
What is CVE-2018-10825?
CVE-2018-10825 is a vulnerability with a CVSS score of 5.3 (MEDIUM). Mimo Baby 2 devices do not use authentication or encryption for the Bluetooth Low Energy (BLE) communication from a Turtle to a Lilypad, which allows attackers to inject fake information about the pos...
How severe is CVE-2018-10825?
CVE-2018-10825 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-10825?
Check the references section above for vendor advisories and patch information. Affected products include: Mimobaby Mimo Baby 2 Firmware, Mimobaby Mimo Baby 2.