Export limit exceeded: 357828 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (4 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2023-6960 | 1 Sciener | 1 Ttlock App | 2026-04-15 | 7.5 High |
| TTLock App virtual keys and settings are only deleted client side, and if preserved, can access the lock after intended deletion. | ||||
| CVE-2023-7003 | 1 Sciener | 1 Ttlock App | 2026-04-15 | 6.8 Medium |
| The AES key utilized in the pairing process between a lock using Sciener firmware and a wireless keypad is not unique, and can be reused to compromise other locks using the Sciener firmware. | ||||
| CVE-2023-7004 | 1 Sciener | 1 Ttlock App | 2026-04-15 | 6.5 Medium |
| The TTLock App does not employ proper verification procedures to ensure that it is communicating with the expected device, allowing for connection to a device that spoofs the MAC address of a lock, which compromises the legitimate locks integrity. | ||||
| CVE-2023-7005 | 1 Sciener | 1 Ttlock App | 2026-04-15 | 7.5 High |
| A specially crafted message can be sent to the TTLock App that downgrades the encryption protocol used for communication, and can be utilized to compromise the lock, such as through revealing the unlockKey field. | ||||
Page 1 of 1.