Vulnerability Description
The OKLOK (3.1.1) mobile companion app for Fingerprint Bluetooth Padlock FB50 (2.3) has weak password requirements combined with improper restriction of excessive authentication attempts, which could allow a remote attacker to discover user credentials and obtain access via a brute force attack.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Oklok Project | Oklok | 3.1.1 |
Related Weaknesses (CWE)
References
- https://github.com/fierceoj/ownklokExploitThird Party Advisory
- https://github.com/fierceoj/ownklokExploitThird Party Advisory
FAQ
What is CVE-2020-8790?
CVE-2020-8790 is a vulnerability with a CVSS score of 9.8 (CRITICAL). The OKLOK (3.1.1) mobile companion app for Fingerprint Bluetooth Padlock FB50 (2.3) has weak password requirements combined with improper restriction of excessive authentication attempts, which could ...
How severe is CVE-2020-8790?
CVE-2020-8790 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2020-8790?
Check the references section above for vendor advisories and patch information. Affected products include: Oklok Project Oklok.