vendor:
Max Pro Power
by:
Alok Kumar
3.1
CVSS
MEDIUM
Bluetooth Low Energy Traffic Replay
284
CWE
Product Name: Max Pro Power
Affected Version From: v1.0 486A
Affected Version To: Not specified
Patch Exists: NO
Related CWE: CVE-2023-46916
CPE: h:maxima:max_pro_power_firmware:v1.0_486A
Platforms Tested: Maxima Max Pro Power
2023
Maxima Max Pro Power BLE Traffic Replay (Unauthenticated)
An attacker can send crafted HEX values to the GATT Charactristic handle on the Maxima Max Pro Power watch to perform unauthorized actions like changing time display format, updating time, and notifications. Due to lack of integrity check, an attacker can sniff values on one smartwatch and replay them on another, leading to unauthorized actions.
Mitigation:
Enable encryption and authentication mechanisms for BLE communication to prevent unauthorized access and replay attacks.