CVE-2020-11539
Summary
| CVE | CVE-2020-11539 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-04-22 14:15:00 UTC |
| Updated | 2023-11-07 03:14:00 UTC |
| Description | An issue was discovered on Tata Sonata Smart SF Rush 1.12 devices. It has been identified that the smart band has no pairing (mode 0 Bluetooth LE security level) The data being transmitted over the air is not encrypted. Adding to this, the data being sent to the smart band doesn't have any authentication or signature verification. Thus, any attacker can control a parameter of the device. |
Risk And Classification
Problem Types: CWE-347 | CWE-306 | CWE-319
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Titan | Sf Rush Smart Band | - | All | All | All |
| Hardware | Titan | Sf Rush Smart Band | - | All | All | All |
| Operating System | Titan | Sf Rush Smart Band Firmware | 1.12 | All | All | All |
| Operating System | Titan | Sf Rush Smart Band Firmware | 1.12 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| GitHub - the-girl-who-lived/CVE-2020-11539: Improper Access Control in Tata Sonata Smartband | MISC | github.com | Exploit, Third Party Advisory |
| Hacking a $5 Smartband. Hello, I am Sayli Ambure. This blogpost… | by Sayli Ambure | Medium | medium.com | ||
| Hacking a $5 Smartband - Sayli Ambure - Medium | MISC | medium.com | Exploit, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.