1 results (0.004 seconds)

CVSS: 6.5EPSS: 0%CPEs: 2EXPL: 1

The Xiaomi M365 scooter 2019-02-12 before 1.5.1 allows spoofing of "suddenly accelerate" commands. This occurs because Bluetooth Low Energy commands have no server-side authentication check. Other affected commands include suddenly braking, locking, and unlocking. El scooter Xiaomi M365 2019-02-12 anterior a la versión 1.5.1 permite la suplantación de comandos "suddenly accelerate". Esto sucede porque los comandos Bluetooth Low Energy no tienen una comprobación de identificación en el lado del servidor. • https://blog.zimperium.com/dont-give-me-a-brake-xiaomi-scooter-hack-enables-dangerous-accelerations-and-stops-for-unsuspecting-riders • CWE-306: Missing Authentication for Critical Function •