Back to search
CVE-2023-7009
Published: Mar 15, 2024
Modified: Nov 4, 2025
PUBLISHED
Description
Some Sciener-based locks support plaintext message processing over Bluetooth Low Energy, allowing unencrypted malicious commands to be passed to the lock. These malicious commands, less then 16 bytes in length, will be processed by the lock as if they were encrypted communications. This can be further exploited by an attacker to compromise the lock's integrity.
| Vendor | Product | Versions |
|---|---|---|
Sciener | Kontrol Lux | affected 6.5.x - <= 6.5.07 |
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now