CVE-2017-18642: Infoleak
Published Feb 10, 2020
·Updated
Syska Smart Bulb devices through 2017-08-06 receive RGB parameters over cleartext Bluetooth Low Energy (BLE), leading to sniffing, reverse engineering, and replay attacks.
Affected Software
2 affected components
Syska Smartlight Rainbow Led Smart Bulb Firmware<=2017-08-06
Syska Smartlight Rainbow Led Smart Bulb
Event History
Feb 10, 2020
CVE Published
via MITRE·08:40 PM
Data Sourced
via MITRE·08:40 PM
Description
Frequently Asked Questions
1
What is CVE-2017-18642?
CVE-2017-18642 is a vulnerability affecting Syska Smart Bulb devices through 2017-08-06.
2
What is the severity of CVE-2017-18642?
CVE-2017-18642 has a severity value of 6.5, which is considered medium.
3
How does CVE-2017-18642 affect Syska Smart Bulb devices?
CVE-2017-18642 allows sniffing, reverse engineering, and replay attacks on Syska Smart Bulb devices through 2017-08-06.
4
Is the Syska Smartlight Rainbow Led Smart Bulb vulnerable to CVE-2017-18642?
No, the Syska Smartlight Rainbow Led Smart Bulb is not vulnerable to CVE-2017-18642.
5
How can I fix CVE-2017-18642?
To fix CVE-2017-18642, it is recommended to update the firmware of Syska Smart Bulb devices to a version after 2017-08-06.