CVE-2022-31459: Owl Labs Meeting Owl Inadequate Encryption Strength Vulnerability
Owl Labs Meeting Owl 5.2.0.15 allows attackers to retrieve the passcode hash via a certain c 10 value over Bluetooth.
Other sources
Owl Labs Meeting Owl contains an inadequate encryption strength vulnerability that allows an attacker to retrieve the passcode hash via a certain c 10 value over Bluetooth.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the CVE ID for this vulnerability?
The CVE ID for this vulnerability is CVE-2022-31459.
What is the title of this vulnerability?
The title of this vulnerability is Owl Labs Meeting Owl Inadequate Encryption Strength Vulnerability.
What is the affected software?
The affected software includes Owllabs Meeting Owl Pro Firmware version up to 5.4.2.3 and Owllabs Meeting Owl.
What is the severity of this vulnerability?
The severity of this vulnerability is high with a CVSS score of 6.5.
How does this vulnerability allow an attacker to retrieve the passcode hash?
This vulnerability allows an attacker to retrieve the passcode hash via a certain c 10 value over Bluetooth.
How can I fix this vulnerability?
To fix this vulnerability, it is recommended to update Owllabs Meeting Owl Pro Firmware to a version above 5.4.2.3.
Are all versions of Owllabs Meeting Owl Pro affected by this vulnerability?
No, only the version up to 5.4.2.3 of Owllabs Meeting Owl Pro Firmware is affected by this vulnerability.
Where can I find more information about this vulnerability?
More information about this vulnerability can be found in the references provided: [link1], [link2], [link3].