CVE Vulnerabilities

CVE-2023-26979

Improper Enforcement of Message Integrity During Transmission in a Communication Channel

Published: Aug 03, 2023 | Modified: Aug 05, 2023
CVSS 3.x
3.1
LOW
Source:
NVD
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Bluetens Electrostimulation Device BluetensQ device app version 4.3.15 is vulnerable to Man-in-the-middle attacks in the BLE channel. It allows attackers to decrease or increase the intensity of the stimulator by hijacking the BLE communication.

Weakness

The product establishes a communication channel with an endpoint and receives a message from that endpoint, but it does not sufficiently ensure that the message was not modified during transmission.

Affected Software

Name Vendor Start Version End Version
Bluetensq Bluetens 4.3.15 (including) 4.3.15 (including)

References