Lucene search

K
cveCERT-PLCVE-2023-6998
HistoryDec 30, 2023 - 7:15 p.m.

CVE-2023-6998

2023-12-3019:15:08
CWE-269
CERT-PL
web.nvd.nist.gov
22
cve-2023-6998
ewelink
coolkit technology
android
ios
vulnerability
lockscreen bypass
nvd

CVSS3

7.7

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

AI Score

7.2

Confidence

High

EPSS

0.001

Percentile

21.7%

Improper privilege management vulnerability in CoolKit Technology eWeLink on Android and iOS allows application lockscreen bypass.This issue affects eWeLink before 5.2.0.

Affected configurations

Nvd
Node
coolkitewelinkRange<5.2.0android
OR
coolkitewelinkRange<5.2.0iphone_os
VendorProductVersionCPE
coolkitewelink*cpe:2.3:a:coolkit:ewelink:*:*:*:*:*:android:*:*
coolkitewelink*cpe:2.3:a:coolkit:ewelink:*:*:*:*:*:iphone_os:*:*

CNA Affected

[
  {
    "collectionURL": "https://play.google.com/store/apps/details?id=com.coolkit",
    "defaultStatus": "unaffected",
    "platforms": [
      "Android"
    ],
    "product": "eWeLink - Smart Home",
    "vendor": "CoolKit Technology",
    "versions": [
      {
        "lessThan": "5.2.0 ",
        "status": "affected",
        "version": "0",
        "versionType": "custom"
      }
    ]
  },
  {
    "collectionURL": "https://apps.apple.com/us/app/ewelink-smart-home/id1035163158",
    "defaultStatus": "unaffected",
    "platforms": [
      "iOS"
    ],
    "product": "eWeLink-Smart Home",
    "vendor": "CoolKit Technology",
    "versions": [
      {
        "lessThan": "5.2.0",
        "status": "affected",
        "version": "0",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

7.7

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

AI Score

7.2

Confidence

High

EPSS

0.001

Percentile

21.7%

Related for CVE-2023-6998