<--

The Kontrol Lux lock can be forced to process arbitrary unencrypted messages

Aleph Research Advisory

Identifier

Severity

High

Product

Sciener Smart Locks

Technical Details

The Kontrol Lux lock supports plaintext message processing over Bluetooth Low Energy, allowing unencrypted malicious commands to be passed to the lock. These malicious commands, less then 16 bytes in length, will be processed by the lock as if they were encrypted communications. This can be further exploited by an attacker to compromise the lock’s integrity.

Timeline

  • 29-Oct-23
    : Reported
  • 21-Dec-23
    : CVE-2023-7009 assigned
  • 07-Mar-24
    : Public disclosure

Credit

  • aronsky of Aleph Research, HCL Software
  • idan-strovinsky of Aleph Research, HCL Software
  • tomer-telem of Aleph Research, HCL Software