CVE-2024-36438
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.3epss 0.2%
exploitation probability
0.2%top 91% of all CVEs
observed exploitation
nono source reports it
In short
The eLinkSmart Hidden Smart Cabinet Lock fails to properly check if a user is authorized before allowing actions, which means attackers can duplicate access cards and gain unauthorized entry to cabinets.
Technical detail
The device implements insufficient authorization checks (CWE-284, CWE-285) for card management operations, allowing an unauthenticated or low-privileged attacker to duplicate valid access credentials without proper access control validation, potentially leading to unauthorized cabinet access and compromise of physical security.
Summary generated and translated by AI from the official description.
eLinkSmart Hidden Smart Cabinet Lock 2024-05-22 has Incorrect Access Control and fails to perform an authorization check which can lead to card duplication and other attacks.
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
Affected products
n/a · n/a