« Volver al listado

CVE-2023-6998

Estado: ModificadaAlta (7.7)—

Improper privilege management vulnerability in CoolKit Technology eWeLink on Android and iOS allows application lockscreen bypass.This issue affects eWeLink before 5.2.0.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-6998",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "cvd@cert.pl",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.7,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.2,
        "exploitabilityScore": 2.5
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.7,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.2,
        "exploitabilityScore": 2.5
      }
    ]
  },
  "affected": [
    {
      "source": "cvd@cert.pl",
      "affectedData": [
        {
          "vendor": "CoolKit Technology",
          "product": "eWeLink - Smart Home",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "5.2.0",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "Android"
          ],
          "collectionURL": "https://play.google.com/store/apps/details?id=com.coolkit",
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "CoolKit Technology",
          "product": "eWeLink-Smart Home",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "5.2.0",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "iOS"
          ],
          "collectionURL": "https://apps.apple.com/us/app/ewelink-smart-home/id1035163158",
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2023-12-30T19:15:08.303",
  "references": [
    {
      "url": "https://cert.pl/en/posts/2023/12/CVE-2023-6998/",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "cvd@cert.pl"
    },
    {
      "url": "https://cert.pl/posts/2023/12/CVE-2023-6998/",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "cvd@cert.pl"
    },
    {
      "url": "https://ewelink.cc/app/",
      "tags": [
        "Product"
      ],
      "source": "cvd@cert.pl"
    },
    {
      "url": "https://cert.pl/en/posts/2023/12/CVE-2023-6998/",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://cert.pl/posts/2023/12/CVE-2023-6998/",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://ewelink.cc/app/",
      "tags": [
        "Product"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "cvd@cert.pl",
      "description": [
        {
          "lang": "en",
          "value": "CWE-305"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Improper privilege management vulnerability in CoolKit Technology eWeLink on Android and iOS allows application lockscreen bypass.This issue affects eWeLink before 5.2.0."
    },
    {
      "lang": "es",
      "value": "Vulnerabilidad de administración de privilegios inadecuada en CoolKit Technology eWeLink en Android e iOS permite omitir la pantalla de bloqueo de la aplicación. Este problema afecta a eWeLink antes de 5.2.0."
    }
  ],
  "lastModified": "2026-06-17T06:51:50.417",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:coolkit:ewelink:*:*:*:*:*:android:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EC7555B6-75B2-4D23-99EC-FED1D5097018",
              "versionEndExcluding": "5.2.0"
            },
            {
              "criteria": "cpe:2.3:a:coolkit:ewelink:*:*:*:*:*:iphone_os:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4BD37BFB-D978-4C15-895A-5D86D064743F",
              "versionEndExcluding": "5.2.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cvd@cert.pl"
}