Vulnerability Description
The TTLock App does not employ proper verification procedures to ensure that it is communicating with the expected device, allowing for connection to a device that spoofs the MAC address of a lock, which compromises the legitimate locks integrity.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://alephsecurity.com/2024/03/07/kontrol-lux-lock-2/
- https://alephsecurity.com/2024/03/07/kontrol-lux-lock-2/
- https://www.kb.cert.org/vuls/id/949046
FAQ
What is CVE-2023-7004?
CVE-2023-7004 is a vulnerability with a CVSS score of 6.5 (MEDIUM). The TTLock App does not employ proper verification procedures to ensure that it is communicating with the expected device, allowing for connection to a device that spoofs the MAC address of a lock, wh...
How severe is CVE-2023-7004?
CVE-2023-7004 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-7004?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.