Improper Authentication in Vandy Vape and Swell Kit Mod - CVE-2019-16518
Published: September 24, 2019
Vulnerability details
The vulnerability allows a local attacker to bypass authentication process.
The vulnerability exists due to an error in the Swell Kit Mod devices that use the Vandy Vape platform. A local attacker with physical access can trigger an unintended temperature in the victim's mouth and throat via Bluetooth Low Energy (BLE) packets that specify large power or voltage values.
Affected software
Swell Kit Mod