CVE-2019-17627
MEDIUMYalehome Yale Bluetooth Key - Authentication Bypass
Title source: ruleDescription
The Yale Bluetooth Key application for mobile devices allows unauthorized unlock actions by sniffing Bluetooth Low Energy (BLE) traffic during one authorized unlock action, and then calculating the authentication key via simple computations on the hex digits of a valid authentication request. This affects the Yale ZEN-R lock and unspecified other locks.
References (1)
Core 1
Core References
Exploit, Third Party Advisory x_refsource_misc
https://github.com/PwnMonkeyLab/YaleDoorlockVulnerability/blob/master/HowToDo.md
Scores
CVSS v3
6.5
EPSS
0.0016
EPSS Percentile
36.1%
Attack Vector
ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Details
CWE
CWE-287
Status
published
Products (1)
yalehome/yale_bluetooth_key
Published
Oct 16, 2019
Tracked Since
Feb 18, 2026