Sciener locks' firmware update mechanism do not authenticate or validate firmware updates if passed to the lock through the Bluetooth Low Energy service. A challenge request can be sent to the lock with a command to prepare for an update, rather than an unlock request, allowing an attacker to compromise the device.
Metrics
Affected Vendors & Products
References
History
Tue, 04 Nov 2025 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 04 Nov 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sciener
Sciener kontrol Lux Firmware |
|
| CPEs | cpe:2.3:o:sciener:kontrol_lux_firmware:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Sciener
Sciener kontrol Lux Firmware |
|
| Metrics |
ssvc
|
Wed, 28 Aug 2024 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: certcc
Published: 2024-03-15T17:07:28.081Z
Updated: 2025-11-04T18:22:12.788Z
Reserved: 2023-12-20T15:50:30.248Z
Link: CVE-2023-7017
Updated: 2025-11-04T18:22:12.788Z
Status : Awaiting Analysis
Published: 2024-03-15T17:15:07.857
Modified: 2025-11-04T19:16:26.230
Link: CVE-2023-7017
No data.