CVE-2023-49914
InteraXon Muse 2 devices allow remote attackers to cause a denial of service (incorrect Muse App report of an outstanding, calm meditation state) via a 480 MHz RF carrier that is modulated by a "false" brain wave, aka a Brain-Hack attack.
Does this matter?
Lower severity and a low EPSS score (0.36%). Track it; it rarely justifies an emergency change on its own.
Description
InteraXon Muse 2 devices allow remote attackers to cause a denial of service (incorrect Muse App report of an outstanding, calm meditation state) via a 480 MHz RF carrier that is modulated by a "false" brain wave, aka a Brain-Hack attack. For example, the Muse App does not display the reception of a strong RF carrier, and alert the user that a report may be misleading if this carrier has been modulated by a low-frequency signal.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 0.36% probability · 30th percentile
- CISA KEV
- Not listed
- Affected
- choosemuse/muse 2 firmware
- Source
- cve@mitre.org
References
- https://dl.acm.org/doi/10.1145/3605758.3623497Technical Description
- https://scholar.google.com/citations?view_op=view_citation&hl=en&user=8hu27apy8A4C&citation_for_view=8hu27apy8A4C:Se3iqnhoufwCTechnical Description
- https://dl.acm.org/doi/10.1145/3605758.3623497Technical Description
- https://scholar.google.com/citations?view_op=view_citation&hl=en&user=8hu27apy8A4C&citation_for_view=8hu27apy8A4C:Se3iqnhoufwCTechnical Description
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.