2024-12-08 03:06:42 +00:00

88 lines
3.3 KiB
JSON

{
"id": "CVE-2022-32503",
"sourceIdentifier": "cve@mitre.org",
"published": "2024-05-14T10:43:41.040",
"lastModified": "2024-11-21T07:06:29.827",
"vulnStatus": "Awaiting Analysis",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "An issue was discovered on certain Nuki Home Solutions devices. An attacker with physical access to this JTAG port may be able to connect to the device and bypass both hardware and software security protections. This affects Nuki Keypad before 1.9.2 and Nuki Fob before 1.8.1."
},
{
"lang": "es",
"value": "Se ha descubierto un problema en determinados dispositivos de Nuki Home Solutions. Un atacante con acceso f\u00edsico a este puerto JTAG puede conectarse al dispositivo y eludir las protecciones de seguridad de hardware y software. Esto afecta a Nuki Keypad anterior a 1.9.2 y a Nuki Fob anterior a 1.8.1."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
"baseScore": 7.6,
"baseSeverity": "HIGH",
"attackVector": "PHYSICAL",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "CHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"availabilityImpact": "HIGH"
},
"exploitabilityScore": 0.9,
"impactScore": 6.0
}
]
},
"weaknesses": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary",
"description": [
{
"lang": "en",
"value": "CWE-306"
}
]
}
],
"references": [
{
"url": "https://latesthackingnews.com/2022/07/28/multiple-security-flaws-found-in-nuki-smart-locks/",
"source": "cve@mitre.org"
},
{
"url": "https://nuki.io/en/security-updates/",
"source": "cve@mitre.org"
},
{
"url": "https://research.nccgroup.com/2022/07/25/technical-advisory-multiple-vulnerabilities-in-nuki-smart-locks-cve-2022-32509-cve-2022-32504-cve-2022-32502-cve-2022-32507-cve-2022-32503-cve-2022-32510-cve-2022-32506-cve-2022-32508-cve-2/",
"source": "cve@mitre.org"
},
{
"url": "https://www.hackread.com/nuki-smart-locks-vulnerabilities-plethora-attack-options/",
"source": "cve@mitre.org"
},
{
"url": "https://latesthackingnews.com/2022/07/28/multiple-security-flaws-found-in-nuki-smart-locks/",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://nuki.io/en/security-updates/",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://research.nccgroup.com/2022/07/25/technical-advisory-multiple-vulnerabilities-in-nuki-smart-locks-cve-2022-32509-cve-2022-32504-cve-2022-32502-cve-2022-32507-cve-2022-32503-cve-2022-32510-cve-2022-32506-cve-2022-32508-cve-2/",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.hackread.com/nuki-smart-locks-vulnerabilities-plethora-attack-options/",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
]
}