CVE-2022-32507
May 14, 2024, 4:13 p.m.
None
No Score
Description
An issue was discovered on certain Nuki Home Solutions devices. Some BLE commands, which should have been designed to be only called from privileged accounts, could also be called from unprivileged accounts. This demonstrates that no access controls were implemented for the different BLE commands across the different accounts. This affects Nuki Smart Lock 3.0 before 3.3.5 and Nuki Smart Lock 2.0 before 2.12.4.
Product(s) Impacted
Product | Versions |
---|---|
Nuki Smart Lock 3.0 |
|
Nuki Smart Lock 2.0 |
|
Weaknesses
Common security weaknesses mapped to this vulnerability.
References
Tags
Timeline
Published: May 14, 2024, 10:43 a.m.
Last Modified: May 14, 2024, 4:13 p.m.
Last Modified: May 14, 2024, 4:13 p.m.
Status : Awaiting Analysis
CVE has been recently published to the CVE List and has been received by the NVD.
More infoSource
cve@mitre.org
*Disclaimer: Some vulnerabilities do not have an associated CPE. To enhance the data, we use AI to infer CPEs based on CVE details. This is an automated process and might not always be accurate.