An issue was discovered on certain Nuki Home Solutions devices. Some BLE commands, which should have been designed to be only called from privileged accounts, could also be called from unprivileged accounts. This demonstrates that no access controls were implemented for the different BLE commands across the different accounts. This affects Nuki Smart Lock 3.0 before 3.3.5 and Nuki Smart Lock 2.0 before 2.12.4.
Metrics
Affected Vendors & Products
References
History
Wed, 14 Aug 2024 20:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-284 | |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: mitre
Published: 2024-05-09T19:39:59.187Z
Updated: 2025-02-13T15:46:26.499Z
Reserved: 2022-06-06T00:00:00.000Z
Link: CVE-2022-32507

Updated: 2024-08-03T07:46:43.472Z

Status : Awaiting Analysis
Published: 2024-05-14T10:43:41.833
Modified: 2024-11-21T07:06:30.720
Link: CVE-2022-32507

No data.