CVE-2020-12702
 
Severity Score
4.6
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
2
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Weak encryption in the Quick Pairing mode in the eWeLink mobile application (Android application V4.9.2 and earlier, iOS application V4.9.1 and earlier) allows physically proximate attackers to eavesdrop on Wi-Fi credentials and other sensitive information by monitoring the Wi-Fi spectrum during the pairing process.
Un cifrado débil en el modo Quick Pairing en la aplicación móvil eWeLink (aplicación Android versiones V4.9.2 y anteriores, aplicación iOS versiones V4.9.1 y anteriores), permite a atacantes próximos físicamente espiar las credenciales de Wi-Fi y otra información confidencial al monitorear el espectro Wi-Fi durante el proceso de emparejamiento
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2020-05-07 CVE Reserved
- 2021-02-24 CVE Published
- 2024-08-04 CVE Updated
- 2024-08-04 First Exploit
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-327: Use of a Broken or Risky Cryptographic Algorithm
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
https://dl.acm.org/doi/abs/10.1145/3411498.3419965 | Third Party Advisory | |
https://play.google.com/store/apps/details?id=com.coolkit&hl=en_US | Product |
URL | Date | SRC |
---|---|---|
https://github.com/salgio/ESPTouchCatcher | 2024-08-04 | |
https://www.youtube.com/watch?v=DghYH7WY6iE&feature=youtu.be | 2024-08-04 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Coolkit Search vendor "Coolkit" | Ewelink Search vendor "Coolkit" for product "Ewelink" | <= 4.9.1 Search vendor "Coolkit" for product "Ewelink" and version " <= 4.9.1" | iphone_os |
Affected
| ||||||
Coolkit Search vendor "Coolkit" | Ewelink Search vendor "Coolkit" for product "Ewelink" | <= 4.9.2 Search vendor "Coolkit" for product "Ewelink" and version " <= 4.9.2" | android |
Affected
|