// For flags

CVE-2018-16242

oBike Electronic Lock Bypass

Severity Score

5.3
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

oBike relies on Hangzhou Luoping Smart Locker to lock bicycles, which allows attackers to bypass the locking mechanism by using Bluetooth Low Energy (BLE) to replay ciphertext based on a predictable nonce used in the locking protocol.

oBike depende de Hangzhou Luoping Smart Locker para bloquear bicicletas, lo que permite que los atacantes omitan el mecanismo de bloqueo mediante el uso de Bluetooth Low Energy (BLE) para reproducir texto cifrado en base a un nonce predecible empleado en el protocolo de bloqueo.

oBike Electronic Lock suffers from an access control bypass vulnerability via a replay attack on a predictable nonce.

*Credits: N/A
CVSS Scores
Attack Vector
Adjacent
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
None
Attack Vector
Adjacent
Attack Complexity
Medium
Authentication
None
Confidentiality
None
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2018-08-30 CVE Reserved
  • 2018-09-13 CVE Published
  • 2024-07-24 EPSS Updated
  • 2024-08-05 CVE Updated
  • 2024-08-05 First Exploit
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-294: Authentication Bypass by Capture-replay
CAPEC
References (1)
URL Tag Source
URL Date SRC
URL Date SRC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
O.bike
Search vendor "O.bike"
Smart Locker Firmware
Search vendor "O.bike" for product "Smart Locker Firmware"
--
Affected
in O.bike
Search vendor "O.bike"
Smart Locker
Search vendor "O.bike" for product "Smart Locker"
--
Safe
O.bike
Search vendor "O.bike"
Obike-stationless Bike Sharing
Search vendor "O.bike" for product "Obike-stationless Bike Sharing"
2.5.4
Search vendor "O.bike" for product "Obike-stationless Bike Sharing" and version "2.5.4"
android
Affected