vendor:
Max Pro Power
by:
Alok Kumar
3.1
CVSS
MEDIUM
Unauthenticated Remote Code Execution
284
CWE
Product Name: Max Pro Power
Affected Version From: v1.0 486A
Affected Version To: Not specified
Patch Exists: NO
Related CWE: CVE-2023-46916
CPE: h:maxima:max_pro_power_firmware:v1.0_486A
Platforms Tested: Maxima Max Pro Power smartwatch
2023
Maxima Max Pro Power BLE Traffic Replay Vulnerability
An attacker can send crafted HEX values to a specific GATT Charactristic handle on the Maxima Max Pro Power smartwatch to perform unauthorized actions like changing Time display format, updating Time, and notifications. Due to lack of integrity checks, an attacker can sniff values on one smartwatch and replay them on another, leading to unauthorized actions.
Mitigation:
Ensure that devices are in a secure environment and implement proper encryption mechanisms to prevent unauthorized access. Regularly update firmware to patch known vulnerabilities.