SB2019092412 - Improper authentication in Vandy Vape platform



SB2019092412 - Improper authentication in Vandy Vape platform

Published: September 24, 2019 Updated: September 24, 2019

Security Bulletin ID SB2019092412
Severity
Low
Patch available
NO
Number of vulnerabilities 1
Exploitation vector Physical access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Improper Authentication (CVE-ID: CVE-2019-16518)

The vulnerability allows a local attacker to bypass authentication process.

The vulnerability exists due to an error in the Swell Kit Mod devices that use the Vandy Vape platform. A local attacker with physical access can trigger an unintended temperature in the victim's mouth and throat via Bluetooth Low Energy (BLE) packets that specify large power or voltage values.



Remediation

Cybersecurity Help is not aware of any official remediation provided by the vendor.