ID

VAR-202112-0132


CVE

CVE-2021-44518


TITLE

Android  for  eGeeTouch 3rd Generation Travel Padlock  Vulnerability related to transmission of sensitive information in plain text in applications

Trust: 0.8

sources: JVNDB: JVNDB-2021-015854

DESCRIPTION

An issue was discovered in the eGeeTouch 3rd Generation Travel Padlock application for Android. The lock sends a pairing code before each operation (lock or unlock) activated via the companion app. The code is sent unencrypted, allowing any attacker with the same app (either Android or iOS) to add the lock and take complete control. For successful exploitation, the attacker must be able to touch the lock's power button, and must be able to capture BLE network communication

Trust: 1.62

sources: NVD: CVE-2021-44518 // JVNDB: JVNDB-2021-015854

IOT TAXONOMY

category:['home & office device']sub_category:smart lock

Trust: 0.1

sources: OTHER: None

AFFECTED PRODUCTS

vendor:digipasmodel:egeetouch managerscope:eqversion: -

Trust: 1.8

vendor:digipasmodel:egeetouch managerscope: - version: -

Trust: 0.8

sources: JVNDB: JVNDB-2021-015854 // NVD: CVE-2021-44518

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2021-44518
value: MEDIUM

Trust: 1.0

NVD: CVE-2021-44518
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-202112-083
value: MEDIUM

Trust: 0.6

nvd@nist.gov: CVE-2021-44518
severity: LOW
baseScore: 2.9
vectorString: AV:A/AC:M/AU:N/C:P/I:N/A:N
accessVector: ADJACENT_NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 5.5
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

nvd@nist.gov: CVE-2021-44518
baseSeverity: MEDIUM
baseScore: 6.8
vectorString: CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H
attackVector: ADJACENT
attackComplexity: HIGH
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: 1.6
impactScore: 5.2
version: 3.1

Trust: 1.0

NVD: CVE-2021-44518
baseSeverity: MEDIUM
baseScore: 6.8
vectorString: CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H
attackVector: ADJACENT NETWORK
attackComplexity: HIGH
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: JVNDB: JVNDB-2021-015854 // CNNVD: CNNVD-202112-083 // NVD: CVE-2021-44518

PROBLEMTYPE DATA

problemtype:CWE-319

Trust: 1.0

problemtype:Sending important information in clear text (CWE-319) [NVD evaluation ]

Trust: 0.8

sources: JVNDB: JVNDB-2021-015854 // NVD: CVE-2021-44518

THREAT TYPE

remote or local

Trust: 0.6

sources: CNNVD: CNNVD-202112-083

TYPE

other

Trust: 0.6

sources: CNNVD: CNNVD-202112-083

PATCH

title:Top Pageurl:https://www.egeetouch.com/

Trust: 0.8

sources: JVNDB: JVNDB-2021-015854

EXTERNAL IDS

db:NVDid:CVE-2021-44518

Trust: 3.3

db:JVNDBid:JVNDB-2021-015854

Trust: 0.8

db:CNNVDid:CNNVD-202112-083

Trust: 0.6

db:OTHERid:NONE

Trust: 0.1

sources: OTHER: None // JVNDB: JVNDB-2021-015854 // CNNVD: CNNVD-202112-083 // NVD: CVE-2021-44518

REFERENCES

url:https://ashallen.net/the-egeetouch-tsa-smart-lock-is-anything-but

Trust: 2.4

url:https://nvd.nist.gov/vuln/detail/cve-2021-44518

Trust: 1.4

url:https://ieeexplore.ieee.org/abstract/document/10769424

Trust: 0.1

sources: OTHER: None // JVNDB: JVNDB-2021-015854 // CNNVD: CNNVD-202112-083 // NVD: CVE-2021-44518

SOURCES

db:OTHERid: -
db:JVNDBid:JVNDB-2021-015854
db:CNNVDid:CNNVD-202112-083
db:NVDid:CVE-2021-44518

LAST UPDATE DATE

2025-01-30T21:40:47.747000+00:00


SOURCES UPDATE DATE

db:JVNDBid:JVNDB-2021-015854date:2022-12-01T02:46:00
db:CNNVDid:CNNVD-202112-083date:2022-07-14T00:00:00
db:NVDid:CVE-2021-44518date:2024-11-21T06:31:08.640

SOURCES RELEASE DATE

db:JVNDBid:JVNDB-2021-015854date:2022-12-01T00:00:00
db:CNNVDid:CNNVD-202112-083date:2021-12-02T00:00:00
db:NVDid:CVE-2021-44518date:2021-12-02T17:15:08.217