IoT & Hardware

Denial of Service

Denial of service (Device Crashing) on Fastrack reflex 2.0 activity tracker

Fuzzing characteristic value leads to Device crash It was identified Fuzzing char value last 3 bytes of the watch was getting crashed after 5 minutes it restarts, Bluetooth doesn’t work and doesn’t…

7.5
/ 10
High
CVSS v3.1
ADVISORY ID
PS49
PUBLISHED
2022-10-04
CVE IDs
CVE-2021-35953
VENDORS
Fastrack
PUBLIC EXPLOIT
None indexed
CWE
PRODUCT
Fastrack Reflex 2.0 Activity Tracker
CVSS VECTOR
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Abstract blurred background with dark tones and smooth gradient waves of blue, purple, and orange hues.
Summary

Overview

Fuzzing characteristic value leads to Device crash

It was identified Fuzzing char value last 3 bytes of the watch was getting crashed after 5 minutes it restarts, Bluetooth doesn’t work and doesn’t show in the network, and attacker can crash the watch and make unusable.

Vulnerability details

Vulnerability details

CVE-2021-35953
High | 7.5

Fuzzing characteristic value leads to Device crash It was identified Fuzzing char value last 3 bytes of the watch was getting crashed after 5 minutes it restarts, Bluetooth doesn’t work and doesn’t show in the network, and attacker can crash the watch and

Impact:
Denial of service
DISCLOSURE

Disclosure timeline

2020-11-17 reported to the vendor

2021-06-30 No response from the vendor and moving forward to public disclosure.

Credits

Shakir Zari