CVE-2018-9119
Summary
| CVE | CVE-2018-9119 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-04-04 18:29:00 UTC |
| Updated | 2023-08-31 23:15:00 UTC |
| Description | An attacker with physical access to a BrilliantTS FUZE card (MCU firmware 0.1.73, BLE firmware 0.7.4) can unlock the card, extract credit card numbers, and tamper with data on the card via Bluetooth because no authentication is needed, as demonstrated by gatttool. |
Risk And Classification
Problem Types: CWE-306
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Brilliantts | Fuze Card | - | All | All | All |
| Hardware | Brilliantts | Fuze Card | - | All | All | All |
| Operating System | Brilliantts | Fuze Card Ble Firmware | 0.7.4 | All | All | All |
| Operating System | Brilliantts | Fuze Card Ble Firmware | 0.7.4 | All | All | All |
| Operating System | Brilliantts | Fuze Card Mcu Firmware | 0.1.73 | All | All | All |
| Operating System | Brilliantts | Fuze Card Mcu Firmware | 0.1.73 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| ICE9 Blog: Stealing Credit Cards from FUZE via Bluetooth | MISC | blog.ice9.us | Third Party Advisory |
| reddit: the front page of the internet | MISC | www.reddit.com | Issue Tracking |
| ice9.us/advisories/ICE9-2018-001.txt | MISC | ice9.us | Third Party Advisory |
| Fuze Multi-Card Technology Security Review | MISC | www.elttam.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.