1 results (0.003 seconds)
CVSS: 6.5EPSS: 0%CPEs: 2EXPL: 1
CVE-2019-12500
https://notcve.org/view.php?id=CVE-2019-12500
The Xiaomi M365 scooter 2019-02-12 before 1.5.1 allows spoofing of "suddenly accelerate" commands. This occurs because Bluetooth Low Energy commands have no server-side authentication check. Other affected commands include suddenly braking, locking, and unlocking. El scooter Xiaomi M365 2019-02-12 anterior a la versión 1.5.1 permite la suplantación de comandos "suddenly accelerate". Esto sucede porque los comandos Bluetooth Low Energy no tienen una comprobación de identificación en el lado del servidor. • https://blog.zimperium.com/dont-give-me-a-brake-xiaomi-scooter-hack-enables-dangerous-accelerations-and-stops-for-unsuspecting-riders • CWE-306: Missing Authentication for Critical Function •