CVE-2016-10702
Last modified
CVE-2016-10702 is a vulnerability of currently unknown severity. Pebble Smartwatch devices through 4.3 mishandle UUID storage, which allows attackers to read an arbitrary application's flash storage, and access an arbitrary application's JavaScript instance, by modifying a UUID value within the header of a crafted application binary.. EPSS estimates a 0.65% chance of exploitation in the next 30 days.
Description
Pebble Smartwatch devices through 4.3 mishandle UUID storage, which allows attackers to read an arbitrary application's flash storage, and access an arbitrary application's JavaScript instance, by modifying a UUID value within the header of a crafted application binary.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Pebble | Pebble Firmware | <= 4.3 |
References
- https://blog.fletchto99.com/2016/november/pebble-app-sandbox-escape/Third Party Advisory
- https://blog.fletchto99.com/2016/november/pebble-app-sandbox-escape/Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2016-10702?
How severe is CVE-2016-10702?
How do I fix CVE-2016-10702?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2016
- CVE-2016-10697react-native-baidu-voice-synthesizer is a baidu voice speech…
- CVE-2016-10698mystem-fix is a node.js wrapper for MyStem morphology text a…
- CVE-2016-10699D-Link DSL-2740E 1.00_BG_20150720 devices are prone to persi…
- CVE-2016-1070Use-after-free vulnerability in Adobe Reader and Acrobat bef…
- CVE-2016-10700auth_login.php in Cacti before 1.0.0 allows remote authentic…
- CVE-2016-10701In Hitachi Vantara Pentaho BA Platform through 8.0, a CSRF i…
- CVE-2016-10703A regular expression Denial of Service (DoS) vulnerability i…7.5
- CVE-2016-10704Magento Community Edition and Enterprise Edition before 2.0.…6.1
- CVE-2016-10705The Jetpack plugin before 4.0.4 for WordPress has XSS via th…
- CVE-2016-10706The Jetpack plugin before 4.0.3 for WordPress has XSS via a …
- CVE-2016-10707jQuery 3.0.0-rc.1 is vulnerable to Denial of Service (DoS) d…7.5
- CVE-2016-10708sshd in OpenSSH before 7.4 allows remote attackers to cause …7.5
Are you affected by CVE-2016-10702?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
