SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-44518

The code is sent unencrypted, allowing any attacker with the same app (either Android or iOS) to add the lock and take complete control.

MEDIUM 6.8EPSS 0.30%

Does this matter?

Lower severity and a low EPSS score (0.30%). Track it; it rarely justifies an emergency change on its own.

Description

An issue was discovered in the eGeeTouch 3rd Generation Travel Padlock application for Android. The lock sends a pairing code before each operation (lock or unlock) activated via the companion app. The code is sent unencrypted, allowing any attacker with the same app (either Android or iOS) to add the lock and take complete control. For successful exploitation, the attacker must be able to touch the lock's power button, and must be able to capture BLE network communication.

CVSS 3.1
6.8 MEDIUMCVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H
EPSS
0.30% probability · 22th percentile
CISA KEV
Not listed
Weakness
CWE-319
Affected
digipas/egeetouch manager
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.