<--

Protocol downgrade on the TTLock app can expose the unlock key

Aleph Research Advisory

Identifier

Severity

High

Product

Sciener Smart Locks

Technical Details

A specially crafted message can be sent to the TTLock App that downgrades the encryption protocol used for communication and can be utilized to compromise the lock, such as by providing the unlockKey value. During the challenge request process, if a message is sent to the app unencrypted, and with a specific set of information, the corresponding message that contains the unlockKey value will be provided unencrypted.

Timeline

  • 29-Oct-23
    : Reported
  • 21-Dec-23
    : CVE-2023-7005 assigned
  • 07-Mar-24
    : Public disclosure

Credit

  • aronsky of Aleph Research, HCL Software
  • idan-strovinsky of Aleph Research, HCL Software
  • tomer-telem of Aleph Research, HCL Software