We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2023-7005

CVE-2023-7005



Description

A specially crafted message can be sent to the TTLock App that downgrades the encryption protocol used for communication, and can be utilized to compromise the lock, such as through revealing the unlockKey field.

Reserved 2023-12-20 | Published 2024-12-19 | Updated 2024-12-20 | Assigner certcc

Problem types

CWE-757: Selection of Less-Secure Algorithm During Negotiation ('Algorithm Downgrade')

Product status

6.4.5
affected

References

alephsecurity.com/2024/03/07/kontrol-lux-lock-2/

cve.org (CVE-2023-7005)

nvd.nist.gov (CVE-2023-7005)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2023-7005

Support options

Helpdesk Chat, Email, Knowledgebase