vendor:
Max Pro Power
by:
Alok Kumar
3.1
CVSS
MEDIUM
Bluetooth Low Energy (BLE) Traffic Replay
284
CWE
Product Name: Max Pro Power
Affected Version From: v1.0 486A
Affected Version To: v1.0 486A
Patch Exists: NO
Related CWE: CVE-2023-46916
CPE: o:maxima:max_pro_power_firmware:v1.0_486A
Platforms Tested: Maxima Max Pro Power
2023
Maxima Max Pro Power – BLE Traffic Replay (Unauthenticated)
An attacker can send crafted HEX values to the GATT Charactristic handle '0x0012' on the Maxima Max Pro Power watch to perform unauthorized actions like changing Time display format, updating Time, and notifications. The lack of integrity checks allows the attacker to sniff values from one smartwatch and replay them on another, leading to unauthorized actions.
Mitigation:
Ensure that devices perform integrity checks on received data to prevent unauthorized actions. Implement secure authentication mechanisms to verify commands sent to the device.