3.1
CVE-2023-26979
- EPSS 0.18%
- Veröffentlicht 03.08.2023 02:15:09
- Zuletzt bearbeitet 21.11.2024 07:52:08
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Bluetens Electrostimulation Device BluetensQ device app version 4.3.15 is vulnerable to Man-in-the-middle attacks in the BLE channel. It allows attackers to decrease or increase the intensity of the stimulator by hijacking the BLE communication.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.18% | 0.078 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 3.1 | 1.6 | 1.4 |
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
|
CWE-924 Improper Enforcement of Message Integrity During Transmission in a Communication Channel
The product establishes a communication channel with an endpoint and receives a message from that endpoint, but it does not sufficiently ensure that the message was not modified during transmission.
http://bluetens.com
https://www.secura.com/blog/serious-safety-impact-found-in-bluetooth-low-energy-based-medical-devices