CVE-2022-32510

May 14, 2024, 4:13 p.m.

Awaiting Analysis
CVE has been recently published to the CVE List and has been received by the NVD.

Products

Nuki Bridge

  • v1 before 1.22.0
  • v2 before 2.13.2

Nuki Bridge v1

  • before 1.22.0

Nuki Bridge v2

  • before 2.13.2

Source

cve@mitre.org

Tags

CVE-2022-32510 details

Published : May 14, 2024, 10:43 a.m.
Last Modified : May 14, 2024, 4:13 p.m.

Description

An issue was discovered on certain Nuki Home Solutions devices. The HTTP API exposed by a Bridge used an unencrypted channel to provide an administrative interface. A token can be easily eavesdropped by a malicious actor to impersonate a legitimate user and gain access to the full set of API endpoints. This affects Nuki Bridge v1 before 1.22.0 and v2 before 2.13.2.

CVSS Score

1 2 3 4 5 6 7 8 9 10

Weakness

Weakness Name Description
This website uses the NVD API, but is not approved or certified by it.