Exploitation Summary
EIP tracks 1 public exploit for CVE-2023-33383. PoCs published by The Security Team [exploitsecurity.io].
AI-analyzed exploit summary This exploit leverages an out-of-bounds read vulnerability in Shelly PRO 4PM firmware v0.11.0 to bypass authentication via Bluetooth Low Energy (BLE) GATT commands. It sends a series of crafted payloads to specific characteristics to trigger the vulnerability.
Description
Shelly 4PM Pro four-channel smart switch 0.11.0 allows an attacker to trigger a BLE out of bounds read fault condition that results in a device reload.
Exploits (1)
This exploit leverages an out-of-bounds read vulnerability in Shelly PRO 4PM firmware v0.11.0 to bypass authentication via Bluetooth Low Energy (BLE) GATT commands. It sends a series of crafted payloads to specific characteristics to trigger the vulnerability.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L