ID

VAR-202209-1855


CVE

CVE-2022-37193


TITLE

iPhone OS  for  chipolo  Vulnerability regarding insufficient protection of authentication information in

Trust: 0.8

sources: JVNDB: JVNDB-2022-018110

DESCRIPTION

Chipolo ONE Bluetooth tracker (2020) Chipolo iOS app version 4.13.0 is vulnerable to Incorrect Access Control. Chipolo devices suffer from access revocation evasion attacks once the malicious sharee obtains the access credentials. iPhone OS for chipolo There are vulnerabilities in inadequate protection of credentials.Information may be obtained and information may be tampered with

Trust: 1.71

sources: NVD: CVE-2022-37193 // JVNDB: JVNDB-2022-018110 // VULMON: CVE-2022-37193

IOT TAXONOMY

category:['industrial device']sub_category:tracker

Trust: 0.1

sources: OTHER: None

AFFECTED PRODUCTS

vendor:chipolomodel:chipoloscope:eqversion:4.13.0

Trust: 1.8

vendor:chipolomodel:chipoloscope:eqversion: -

Trust: 0.8

vendor:chipolomodel:chipoloscope: - version: -

Trust: 0.8

sources: JVNDB: JVNDB-2022-018110 // NVD: CVE-2022-37193

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2022-37193
value: HIGH

Trust: 1.0

134c704f-9b21-4f2e-91b3-4a467353bcc0: CVE-2022-37193
value: HIGH

Trust: 1.0

NVD: CVE-2022-37193
value: HIGH

Trust: 0.8

CNNVD: CNNVD-202209-2813
value: HIGH

Trust: 0.6

nvd@nist.gov: CVE-2022-37193
baseSeverity: HIGH
baseScore: 7.4
vectorString: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
attackVector: NETWORK
attackComplexity: HIGH
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: NONE
exploitabilityScore: 2.2
impactScore: 5.2
version: 3.1

Trust: 2.0

NVD: CVE-2022-37193
baseSeverity: HIGH
baseScore: 7.4
vectorString: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
attackVector: NETWORK
attackComplexity: HIGH
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: JVNDB: JVNDB-2022-018110 // CNNVD: CNNVD-202209-2813 // NVD: CVE-2022-37193 // NVD: CVE-2022-37193

PROBLEMTYPE DATA

problemtype:CWE-522

Trust: 1.0

problemtype:Inadequate protection of credentials (CWE-522) [NVD evaluation ]

Trust: 0.8

sources: JVNDB: JVNDB-2022-018110 // NVD: CVE-2022-37193

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-202209-2813

TYPE

other

Trust: 0.6

sources: CNNVD: CNNVD-202209-2813

EXTERNAL IDS

db:NVDid:CVE-2022-37193

Trust: 3.4

db:JVNDBid:JVNDB-2022-018110

Trust: 0.8

db:CNNVDid:CNNVD-202209-2813

Trust: 0.6

db:OTHERid:NONE

Trust: 0.1

db:VULMONid:CVE-2022-37193

Trust: 0.1

sources: OTHER: None // VULMON: CVE-2022-37193 // JVNDB: JVNDB-2022-018110 // CNNVD: CNNVD-202209-2813 // NVD: CVE-2022-37193

REFERENCES

url:https://github.com/zhouxinan/ccs22maagiot/blob/main/chipoloone.md

Trust: 2.5

url:https://chipolo.net/en-us/products/chipolo-one-4-pack

Trust: 2.5

url:https://nvd.nist.gov/vuln/detail/cve-2022-37193

Trust: 0.8

url:https://cxsecurity.com/cveshow/cve-2022-37193/

Trust: 0.6

url:https://ieeexplore.ieee.org/abstract/document/10769424

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

sources: OTHER: None // VULMON: CVE-2022-37193 // JVNDB: JVNDB-2022-018110 // CNNVD: CNNVD-202209-2813 // NVD: CVE-2022-37193

SOURCES

db:OTHERid: -
db:VULMONid:CVE-2022-37193
db:JVNDBid:JVNDB-2022-018110
db:CNNVDid:CNNVD-202209-2813
db:NVDid:CVE-2022-37193

LAST UPDATE DATE

2025-05-22T21:24:15.274000+00:00


SOURCES UPDATE DATE

db:VULMONid:CVE-2022-37193date:2022-09-28T00:00:00
db:JVNDBid:JVNDB-2022-018110date:2023-10-18T08:11:00
db:CNNVDid:CNNVD-202209-2813date:2022-10-08T00:00:00
db:NVDid:CVE-2022-37193date:2025-05-22T14:15:58.603

SOURCES RELEASE DATE

db:VULMONid:CVE-2022-37193date:2022-09-27T00:00:00
db:JVNDBid:JVNDB-2022-018110date:2023-10-18T00:00:00
db:CNNVDid:CNNVD-202209-2813date:2022-09-27T00:00:00
db:NVDid:CVE-2022-37193date:2022-09-27T23:15:14.417