<--

A Gateway G2 can be impersonated using its MAC address

Aleph Research Advisory

Identifier

Severity

Moderate

Product

Sciener Smart Locks

Technical Details

The Sciener server does not validate connection requests from the Gateway G2, allowing an impersonation attack. An attacker can connect to Sciener servers, impersonate a Gateway G2 that has established a connection with a lock by using its MAC address, and receive messages instead of the legitimate Gateway G2. This can facilitate access of the unlockKey value.

Timeline

  • 29-Oct-23
    : Reported
  • 21-Dec-23
    : CVE-2023-7007 assigned
  • 07-Mar-24
    : Public disclosure

Credit

  • aronsky of Aleph Research, HCL Software
  • idan-strovinsky of Aleph Research, HCL Software
  • tomer-telem of Aleph Research, HCL Software