Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Light

Researcher fromPwnMonkeyLab@xfuturesec Co., Ltd
#55690of 56,326
3.3Total CVSS
Vulnerabilities · 1
PT-2019-15236
3.3
2019-10-16
Yale · Yale Bluetooth Key Application · CVE-2019-17627
**Name of the Vulnerable Software and Affected Versions** Yale Bluetooth Key application (affected versions not specified) Yale ZEN-R lock (affected versions not specified) **Description** The issue allows unauthorized unlock actions by sniffing Bluetooth Low Energy (BLE) traffic during one authorized unlock action, and then calculating the authentication key via simple computations on the hex digits of a valid authentication request. **Recommendations** For the Yale Bluetooth Key application, at the moment, there is no information about a newer version that contains a fix for this vulnerability. For the Yale ZEN-R lock, at the moment, there is no information about a newer version that contains a fix for this vulnerability.