IoT & Hardware

Hardware / Firmware Exposure

Authentication & Access Bypass

Lack of Bluetooth LE pairing and access control in Fastrack reflex 2.0 activity tracker

Lack of Bluetooth LE pairing and access control Time, date, and month on the smartwatch It was identified on analyzing the Bluetooth LE Characteristics of the device that, on handle 0x0017 the value…

5.3
/ 10
Medium
CVSS v3.1
ADVISORY ID
PS51
PUBLISHED
2022-10-05
CVE IDs
CVE-2021-35952
VENDORS
Fastrack
PUBLIC EXPLOIT
None indexed
CWE
PRODUCT
Fastrack Reflex 2.0 Activity Tracker
CVSS VECTOR
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Abstract blurred background with dark tones and smooth gradient waves of blue, purple, and orange hues.
Summary

Overview

Lack of Bluetooth LE pairing and access control Time, date, and month on the smartwatch

It was identified on analyzing the Bluetooth LE Characteristics of the device that, on handle 0x0017 the value modifying the time date and month changes. An attacker can change the time date and month.

Vulnerability details

Vulnerability details

CVE-2021-35952
Medium | 5.3

Lack of Bluetooth LE pairing and access control Time, date, and month on the smartwatch It was identified on analyzing the Bluetooth LE Characteristics of the device that, on handle 0x0017 the value modifying the time date and month changes.

Impact:
Limited data tampering
DISCLOSURE

Disclosure timeline

2020-11-17 reported to the vendor

2021-06-30 No response from the vendor and moving forward to public disclosure.

Credits

Shakir Zari