CVE-2019-17627
Last modified
CVE-2019-17627 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. The Yale Bluetooth Key application for mobile devices allows unauthorized unlock actions by sniffing Bluetooth Low Energy (BLE) traffic during one authorized unlock action, and then calculating the authentication key via simple computations on the hex digits of a valid authentication request. This affects the Yale ZEN-R lock and unspecified other locks.. EPSS estimates a 0.68% chance of exploitation in the next 30 days.
Description
The Yale Bluetooth Key application for mobile devices allows unauthorized unlock actions by sniffing Bluetooth Low Energy (BLE) traffic during one authorized unlock action, and then calculating the authentication key via simple computations on the hex digits of a valid authentication request. This affects the Yale ZEN-R lock and unspecified other locks.
Metrics
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Yalehome | Yale Bluetooth Key | All versions |
References
- https://github.com/PwnMonkeyLab/YaleDoorlockVulnerability/blob/master/HowToDo.mdExploit, Third Party Advisory
- https://github.com/PwnMonkeyLab/YaleDoorlockVulnerability/blob/master/HowToDo.mdExploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-17627?
How severe is CVE-2019-17627?
How do I fix CVE-2019-17627?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-17613qibosoft 7 allows remote code execution because do/jf.php ma…9.8
- CVE-2019-1762A vulnerability in the Secure Storage feature of Cisco IOS a…4.4
- CVE-2019-17621The UPnP endpoint URL /gena.cgi in the D-Link DIR-859 Wi-Fi …9.8
- CVE-2019-17624"" In X.Org X Server 1.20.4, there is a stack-based buffer o…7.8
- CVE-2019-17625There is a stored XSS in Rambox 0.6.9 that can lead to code …9
- CVE-2019-17626ReportLab through 3.5.26 allows remote code execution becaus…9.8
- CVE-2019-17629CMS Made Simple (CMSMS) 2.2.11 allows stored XSS by an admin…4.8
- CVE-2019-1763A vulnerability in the web-based management interface of Ses…7.5
- CVE-2019-17630CMS Made Simple (CMSMS) 2.2.11 allows stored XSS by an admin…4.8
- CVE-2019-17631From Eclipse OpenJ9 0.15 to 0.16, access to diagnostic opera…9.1
- CVE-2019-17632In Eclipse Jetty versions 9.4.21.v20190926, 9.4.22.v20191022…6.1
- CVE-2019-17633For Eclipse Che versions 6.16 to 7.3.0, with both authentica…8.8
Are you affected by CVE-2019-17627?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
