← Back

CVE-2018-16242

nvd nist
Published: Sep 14, 2018Modified: Nov 21, 2024

JSON object

Loading...
5.3
Vector
CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Exploitability: 1.6 / Impact: 3.6
Source: NVD

Description

oBike relies on Hangzhou Luoping Smart Locker to lock bicycles, which allows attackers to bypass the locking mechanism by using Bluetooth Low Energy (BLE) to replay ciphertext based on a predictable nonce used in the locking protocol.

Affected (2)

2 products
Smart Locker Firmware
Obike Stationless Bike Sharing
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
O.bike
Smart Locker
All versions
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 2.5.4

References (2)

Source: cve@mitre.org
ExploitMailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitMailing ListThird Party Advisory

Timeline

No history available yet.