ID

VAR-202202-1924


TITLE

Logic flaws in Tuya smart app and Tuya converter (smart socket)

Trust: 0.6

sources: CNVD: CNVD-2021-73145

DESCRIPTION

Tuya Smart is an IoT cloud platform that connects the intelligent needs of brands, OEM manufacturers, developers and chain retailers, and provides a one-stop AI IoT PaaS-level solution, covering hardware development, global cloud, and smart business platform development , providing comprehensive ecological empowerment. The Tuya smart app and Tuya converter (smart socket) have a logic flaw vulnerability. The vulnerability stems from not using a secure encryption algorithm (AES/ECB) during the communication between Tuya smart app and Tuya converter (smart socket). Vulnerabilities can be exploited to obtain encrypted message instructions to reconstruct (modify) message packets and calculate corresponding checksums.

Trust: 0.6

sources: CNVD: CNVD-2021-73145

IOT TAXONOMY

category:['IoT']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2021-73145

AFFECTED PRODUCTS

vendor:tuyamodel:converter ykyc-w1y0-16ascope: - version: -

Trust: 0.6

vendor:tuyamodel:smart appscope:eqversion:3.29.5

Trust: 0.6

sources: CNVD: CNVD-2021-73145

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2021-73145
value: MEDIUM

Trust: 0.6

CNVD: CNVD-2021-73145
severity: MEDIUM
baseScore: 6.1
vectorString: AV:A/AC:L/AU:N/C:N/I:N/A:C
accessVector: ADJACENT_NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 6.5
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2021-73145

PATCH

title:Patch for Logic flaws in Tuya smart app and Tuya converter (smart socket)url:https://www.cnvd.org.cn/patchinfo/show/318106

Trust: 0.6

sources: CNVD: CNVD-2021-73145

EXTERNAL IDS

db:CNVDid:CNVD-2021-73145

Trust: 0.6

sources: CNVD: CNVD-2021-73145

SOURCES

db:CNVDid:CNVD-2021-73145

LAST UPDATE DATE

2023-09-28T22:44:57.023000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2021-73145date:2022-02-09T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2021-73145date:2022-02-09T00:00:00