SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-11334

An authentication bypass in website post requests in the Tzumi Electronics Klic Lock application 1.0.9 for mobile devices allows attackers to access resources (that are not otherwise accessible without proper authentication) via capture-replay.

LOW 3.7EPSS 1.59%

Does this matter?

Lower severity and a low EPSS score (1.59%). Track it; it rarely justifies an emergency change on its own.

Description

An authentication bypass in website post requests in the Tzumi Electronics Klic Lock application 1.0.9 for mobile devices allows attackers to access resources (that are not otherwise accessible without proper authentication) via capture-replay. Physically proximate attackers can use this information to unlock unauthorized Tzumi Electronics Klic Smart Padlock Model 5686 Firmware 6.2.

CVSS 3.1
3.7 LOWCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS
1.59% probability · 74th percentile
CISA KEV
Not listed
Weakness
CWE-294
Affected
tzumi/klic lock · tzumi/klic smart padlock model 5686 firmware
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.