SB2019092412 - Improper authentication in Vandy Vape platform
Published: September 24, 2019 Updated: September 24, 2019
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper Authentication (CVE-ID: CVE-2019-16518)
The vulnerability allows a local attacker to bypass authentication process.
The vulnerability exists due to an error in the Swell Kit Mod devices that use the Vandy Vape platform. A local attacker with physical access can trigger an unintended temperature in the victim's mouth and throat via Bluetooth Low Energy (BLE) packets that specify large power or voltage values.
Remediation
Cybersecurity Help is not aware of any official remediation provided by the vendor.