CVE-2023-6998

Improper privilege management vulnerability in CoolKit Technology eWeLink on Android and iOS allows application lockscreen bypass.This issue affects eWeLink before 5.2.0.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:coolkit:ewelink:*:*:*:*:*:android:*:*
cpe:2.3:a:coolkit:ewelink:*:*:*:*:*:iphone_os:*:*

History

11 Jan 2024, 20:25

Type Values Removed Values Added
First Time Coolkit ewelink
Coolkit
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.7
References () https://cert.pl/posts/2023/12/CVE-2023-6998/ - () https://cert.pl/posts/2023/12/CVE-2023-6998/ - Third Party Advisory
References () https://ewelink.cc/app/ - () https://ewelink.cc/app/ - Product
References () https://cert.pl/en/posts/2023/12/CVE-2023-6998/ - () https://cert.pl/en/posts/2023/12/CVE-2023-6998/ - Third Party Advisory
CWE NVD-CWE-noinfo
CPE cpe:2.3:a:coolkit:ewelink:*:*:*:*:*:android:*:*
cpe:2.3:a:coolkit:ewelink:*:*:*:*:*:iphone_os:*:*

30 Dec 2023, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-12-30 19:15

Updated : 2024-02-28 20:54


NVD link : CVE-2023-6998

Mitre link : CVE-2023-6998

CVE.ORG link : CVE-2023-6998


JSON object : View

Products Affected

coolkit

  • ewelink
CWE
NVD-CWE-noinfo CWE-269

Improper Privilege Management