An issue was discovered on certain Nuki Home Solutions devices. Lack of certificate validation on HTTP communications allows attackers to intercept and tamper data. This affects Nuki Smart Lock 3.0 before 3.3.5, Nuki Bridge v1 before 1.22.0 and Nuki Bridge v2 before 2.13.2.
History

Wed, 14 Aug 2024 20:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-295
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-14T19:05:05.802Z

Reserved:

Link: CVE-2022-32509

cve-icon Vulnrichment

Updated: 2024-08-03T07:46:43.316Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-05-14T10:43:42.160

Modified: 2024-08-14T19:35:02.523

Link: CVE-2022-32509

cve-icon Redhat

No data.