4.3
CVSSv3

CVE-2023-46916

Published: 07/12/2023 Updated: 12/12/2023
CVSS v3 Base Score: 4.3 | Impact Score: 1.4 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

Maxima Max Pro Power 1.0 486A devices allow BLE traffic replay. An attacker can use GATT characteristic handle 0x0012 to perform potentially disruptive actions such as starting a Heart Rate monitor.

Vulnerable Product Search on Vulmon Subscribe to Product

maximawatches maxima_max_pro_power_firmware 1.0_486a

Exploits

Maxima Max Pro Power with firmware version 10 486A suffers from a BLE traffic replay vulnerability that allows for arbitrary unauthorized actions ...