VulnerabilityModified
CVE-2016-6549
The Zizai Tech Nut device allows unauthenticated Bluetooth pairing, which enables unauthenticated connected applications to write data to the device name attribute.
MEDIUM 4.3EPSS 1.08%
Does this matter?
Lower severity and a low EPSS score (1.08%). Track it; it rarely justifies an emergency change on its own.
Description
The Zizai Tech Nut device allows unauthenticated Bluetooth pairing, which enables unauthenticated connected applications to write data to the device name attribute.
- CVSS 3.0
- 4.3 MEDIUMCVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- EPSS
- 1.08% probability · 63th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-306, CWE-287
- Affected
- nutspace/nut mobile
- Source
- cret@cert.org
References
- https://blog.rapid7.com/2016/10/25/multiple-bluetooth-low-energy-ble-tracker-vulnerabilities/Exploit, Third Party Advisory
- https://www.kb.cert.org/vuls/id/402847Third Party Advisory, US Government Resource
- https://www.securityfocus.com/bid/93877Third Party Advisory, VDB Entry
- https://blog.rapid7.com/2016/10/25/multiple-bluetooth-low-energy-ble-tracker-vulnerabilities/Exploit, Third Party Advisory
- https://www.kb.cert.org/vuls/id/402847Third Party Advisory, US Government Resource
- https://www.securityfocus.com/bid/93877Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.