CVE-2023-34625
ShowMojo MojoBox Digital Lockbox 1.4 is vulnerable to Authentication Bypass.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.98%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
ShowMojo MojoBox Digital Lockbox 1.4 is vulnerable to Authentication Bypass. The implementation of the lock opening mechanism via Bluetooth Low Energy (BLE) is vulnerable to replay attacks. A malicious user is able to intercept BLE requests and replicate them to open the lock at any time. Alternatively, an attacker with physical access to the device on which the Android app is installed, can obtain the latest BLE messages via the app logs and use them for opening the lock.
- CVSS 3.1
- 8.1 HIGHCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
- EPSS
- 0.98% probability · 60th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-294
- Affected
- showmojo/mojobox firmware
- Source
- cve@mitre.org
References
- https://mandomat.github.io/2023-03-15-testing-mojobox-security/Exploit, Technical Description, Third Party Advisory
- https://packetstormsecurity.com/2307-exploits/mojobox14-replay.txtThird Party Advisory, VDB Entry
- https://www.whid.ninja/blog/mojobox-yet-another-not-so-smartlockExploit, Technical Description, Third Party Advisory
- https://mandomat.github.io/2023-03-15-testing-mojobox-security/Exploit, Technical Description, Third Party Advisory
- https://packetstormsecurity.com/2307-exploits/mojobox14-replay.txtThird Party Advisory, VDB Entry
- https://www.whid.ninja/blog/mojobox-yet-another-not-so-smartlockExploit, Technical Description, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.