CERT-In Vulnerability Note
CIVN-2023-0333
Unauthorized Access Vulnerability in Syska SW100 Smartwatch
Original Issue Date:October 31, 2023
Severity Rating: HIGH
Software Affected
- Syska Sw100 Smartwatch version V2
Overview
A vulnerability has been reported in Syska SW100 Smartwatch which could allow an attacker to perform malicious activities on the target device.
Description
The vulnerability exists in Syska SW100 Smartwatch due to an improper implementation and/or configuration of Nordic Device Firmware Update (DFU) which is used for performing Over-The-Air (OTA) firmware updates on the Bluetooth Low Energy (BLE) devices. An unauthenticated attacker could exploit this vulnerability by setting arbitrary values to handle on the vulnerable device over Bluetooth.
Successful exploitation of this vulnerability could allow the attacker to perform firmware update, device reboot or data manipulation on the target device.
Credit
This vulnerability is reported by Shakir Zari from Payatu Security Consulting Pvt Ltd., Maharashtra, India.
Solution
Apply mitigations as per vendor instructions or discontinue use of the product if mitigations are unavailable.
Vendor Information
Syska Led Lights Pvt Ltd
https://syska.co.in/
References
Syska Led Lights Pvt Ltd
https://syska.co.in/
CVE Name
CVE-2022-3007
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|