Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2022-45634: Username Disclosure Vulnerability in DBD+ Application Used by Megafeis Smart Locks

An issue discovered in MEGAFEIS, BOFEI DBD+ Application for IOS & Android v1.4.4 allows authenticated attacker to gain access to sensitive account information

CVE
#vulnerability#ios#android#git#auth

An information disclosure issue was discovered allowed an attacker within Bluetooth broadcast range of a target Megafeis-branded Smartlock to acquire sensitive information. This information was the email address and phone number associated with accounts which owned Megafeis smart locks.

The username can then be combined with the API server’s password reset issue (CVE-2022-45637) or the API server’s password policy issue (CVE-2022-45635) to facilitate an attacker’s efforts take over the target user’s account.

As of this advisory’s publishing date, there has been no response from the manufacturer, nor is WithSecure aware of any remedial action taken.

Additional information on this issue, along with related issues discovered by the researcher, can be found in the following locations:

  • The Megafeis-palm: Exploiting Vulnerabilities to Open Bluetooth SmartLocks publication
  • The associated GitHub repository: https://github.com/WithSecureLabs/megafeis-palm

To demonstrate an attacker’s ability to expose the email or phone number associated with a Megafeis smart lock owner’s account, the following steps can be performed within version 1.4.2 of the DBD+ application:

  • Log in to the DBD+ application using a valid account.
  • Once authenticated, press the “Add” button.
  • Once a device advertising its Megafeis model number is discovered, tap on it.
  • If the lock is already bound to a user, the resulting permission request will expose its owner’s login username.

The screenshots below illustrate these steps from the view of the mobile application and reveal the username/email address of a test user researchers created while investigating this issue:

Related news

CVE-2022-45637: megafeis-palm/CVE-2022-45637 at main · WithSecureLabs/megafeis-palm

An insecure password reset issue discovered in MEGAFEIS, BOFEI DBD+ Application for IOS & Android v1.4.4 service via insecure expiry mechanism.

CVE-2022-45635: megafeis-palm/CVE-2022-45635 at main · WithSecureLabs/megafeis-palm

An issue discovered in MEGAFEIS, BOFEI DBD+ Application for IOS & Android v1.4.4 allows attacker to gain access to sensitive account information via insecure password policy.

CVE-2022-45635: megafeis-palm/CVE-2022-45635 at main · WithSecureLabs/megafeis-palm

An issue discovered in MEGAFEIS, BOFEI DBD+ Application for IOS & Android v1.4.4 allows attacker to gain access to sensitive account information via insecure password policy.

CVE-2022-45637: megafeis-palm/CVE-2022-45637 at main · WithSecureLabs/megafeis-palm

An insecure password reset issue discovered in MEGAFEIS, BOFEI DBD+ Application for IOS & Android v1.4.4 service via insecure expiry mechanism.

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907