CVE-2022-32502

An issue was discovered on certain Nuki Home Solutions devices. There is a buffer overflow over the encrypted token parsing logic in the HTTP service that allows remote code execution. This affects Nuki Bridge v1 before 1.22.0 and v2 before 2.13.2.
Configurations

No configuration.

History

21 Nov 2024, 07:06

Type Values Removed Values Added
References () https://latesthackingnews.com/2022/07/28/multiple-security-flaws-found-in-nuki-smart-locks/ - () https://latesthackingnews.com/2022/07/28/multiple-security-flaws-found-in-nuki-smart-locks/ -
References () https://nuki.io/en/security-updates/ - () https://nuki.io/en/security-updates/ -
References () https://research.nccgroup.com/2022/07/25/technical-advisory-multiple-vulnerabilities-in-nuki-smart-locks-cve-2022-32509-cve-2022-32504-cve-2022-32502-cve-2022-32507-cve-2022-32503-cve-2022-32510-cve-2022-32506-cve-2022-32508-cve-2/ - () https://research.nccgroup.com/2022/07/25/technical-advisory-multiple-vulnerabilities-in-nuki-smart-locks-cve-2022-32509-cve-2022-32504-cve-2022-32502-cve-2022-32507-cve-2022-32503-cve-2022-32510-cve-2022-32506-cve-2022-32508-cve-2/ -
References () https://www.hackread.com/nuki-smart-locks-vulnerabilities-plethora-attack-options/ - () https://www.hackread.com/nuki-smart-locks-vulnerabilities-plethora-attack-options/ -

03 Jul 2024, 01:38

Type Values Removed Values Added
CWE CWE-121
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.3
Summary
  • (es) Se ha descubierto un problema en determinados dispositivos de Nuki Home Solutions. Hay un desbordamiento del búfer sobre la lógica de análisis del token cifrado en el servicio HTTP que permite la ejecución remota de código. Esto afecta a Nuki Bridge v1 anterior a 1.22.0 y v2 anterior a 2.13.2.

14 May 2024, 10:43

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-14 10:43

Updated : 2024-11-21 07:06


NVD link : CVE-2022-32502

Mitre link : CVE-2022-32502

CVE.ORG link : CVE-2022-32502


JSON object : View

Products Affected

No product.

CWE
CWE-121

Stack-based Buffer Overflow