Układ SoC ESP32 w urządzeniu Meatmeet Pro miał włączony JTAG. Pozostawienie JTAG włączone na ESP32 w produkcie komercyjnym pozwala atakującemu z dostępem fizycznym do urządzenia podłączyć się przez ten port i przepisać firmware urządzenia na złośliwy kod, który zostanie wykonany przy uruchomieniu. W wyniku tego użytkownik utraci dostęp do funkcjonalności urządzenia, a atakujący może uzyskać nieautoryzowany dostęp do sieci Wi-Fi ofiary, ponownie łącząc się z SSID zdefiniowanym w partycji NVS urządzenia.
▸ Pokaż oryginał (EN)
The ESP32 system on a chip (SoC) that powers the Meatmeet Pro was found to have JTAG enabled. By leaving JTAG enabled on an ESP32 in a commercial product an attacker with physical access to the device can connect over this port and reflash the device's firmware with malicious code which will be executed upon running. As a result, the victim will lose access to the functionality of their device and the attack may gain unauthorized access to the victim's Wi-Fi network by re-connecting to the SSID defined in the NVS partition of the device.
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HMeatmeet Pro Wifi \& Bluetooth Meat Thermometer
HWMeatmeetwszystkie wersjeMeatmeet Pro Wifi \& Bluetooth Meat Thermometer Firmware
OSMeatmeet1.0.34.4
Powiązane podatności
Hardcoded Wi-Fi credentials w firmware urządzenia Meatmeet Pro
As UART download mode is still enabled on the ESP32 chip on which the firmware runs, an adversary can dump the...
An unauthenticated attacker within proximity of the Meatmeet device can perform an unauthorized Over The Air (...
Oprogramowanie sprzętowe stacji bazowej Meatmeet nie jest zaszyfrowane. Atakujący mający fizyczny dostęp do ur...
Atakujący bez uwierzytelnienia w pobliżu urządzenia Meatmeet może wydać wiele poleceń przez Bluetooth Low Ener...