CVE-2022-31459
HIGH IN THE WILDOwl Labs Meeting Owl <5.2.0.15 - Info Disclosure
Title source: llmExploitation Summary
CVE-2022-31459 has been observed exploited in the wild (reported by InTheWild.io).
Description
Owl Labs Meeting Owl 5.2.0.15 allows attackers to retrieve the passcode hash via a certain c 10 value over Bluetooth.
References (3)
Core 3
Core References
Third Party Advisory x_refsource_misc
https://arstechnica.com/information-technology/2022/06/vulnerabilities-in-meeting-owl-videoconference-device-imperil-100k-users/
Exploit, Third Party Advisory x_refsource_misc
https://www.modzero.com/static/meetingowl/Meeting_Owl_Pro_Security_Disclosure_Report_RELEASE.pdf
Release Notes, Vendor Advisory x_refsource_misc
https://resources.owllabs.com/blog/owl-labs-update
Scores
CVSS v3
7.4
EPSS
0.0079
EPSS Percentile
51.3%
Attack Vector
ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Details
InTheWild.io
2023-09-18
CWE
CWE-326
Status
published
Products (1)
owllabs/meeting_owl_pro_firmware
< 5.4.2.3
Published
Jun 02, 2022
Tracked Since
Feb 18, 2026