CVE-2022-32503

An issue was discovered on certain Nuki Home Solutions devices. An attacker with physical access to this JTAG port may be able to connect to the device and bypass both hardware and software security protections. This affects Nuki Keypad before 1.9.2 and Nuki Fob before 1.8.1.
Configurations

No configuration.

History

21 Nov 2024, 07:06

Type Values Removed Values Added
References () https://latesthackingnews.com/2022/07/28/multiple-security-flaws-found-in-nuki-smart-locks/ - () https://latesthackingnews.com/2022/07/28/multiple-security-flaws-found-in-nuki-smart-locks/ -
References () https://nuki.io/en/security-updates/ - () https://nuki.io/en/security-updates/ -
References () https://research.nccgroup.com/2022/07/25/technical-advisory-multiple-vulnerabilities-in-nuki-smart-locks-cve-2022-32509-cve-2022-32504-cve-2022-32502-cve-2022-32507-cve-2022-32503-cve-2022-32510-cve-2022-32506-cve-2022-32508-cve-2/ - () https://research.nccgroup.com/2022/07/25/technical-advisory-multiple-vulnerabilities-in-nuki-smart-locks-cve-2022-32509-cve-2022-32504-cve-2022-32502-cve-2022-32507-cve-2022-32503-cve-2022-32510-cve-2022-32506-cve-2022-32508-cve-2/ -
References () https://www.hackread.com/nuki-smart-locks-vulnerabilities-plethora-attack-options/ - () https://www.hackread.com/nuki-smart-locks-vulnerabilities-plethora-attack-options/ -

29 Oct 2024, 15:35

Type Values Removed Values Added
CWE CWE-288 CWE-306

03 Jul 2024, 01:38

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.6
Summary
  • (es) Se ha descubierto un problema en determinados dispositivos de Nuki Home Solutions. Un atacante con acceso físico a este puerto JTAG puede conectarse al dispositivo y eludir las protecciones de seguridad de hardware y software. Esto afecta a Nuki Keypad anterior a 1.9.2 y a Nuki Fob anterior a 1.8.1.
CWE CWE-288

14 May 2024, 10:43

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-14 10:43

Updated : 2024-11-21 07:06


NVD link : CVE-2022-32503

Mitre link : CVE-2022-32503

CVE.ORG link : CVE-2022-32503


JSON object : View

Products Affected

No product.

CWE
CWE-306

Missing Authentication for Critical Function