CVE-2023-34625 Details
Description
ShowMojo MojoBox Digital Lockbox 1.4 is vulnerable to Authentication Bypass. The implementation of the lock opening mechanism via Bluetooth Low Energy (BLE) is vulnerable to replay attacks. A malicious user is able to intercept BLE requests and replicate them to open the lock at any time. Alternatively, an attacker with physical access to the device on which the Android app is installed, can obtain the latest BLE messages via the app logs and use them for opening the lock.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Oct 30, 2024References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://mandomat.github.io/2023-03-15-testing-mojobox-security/ | CVE | ExploitTechnical DescriptionThird Party Advisory |
| https://packetstormsecurity.com/2307-exploits/mojobox14-replay.txt | CVE | Third Party AdvisoryVDB Entry |
| https://www.whid.ninja/blog/mojobox-yet-another-not-so-smartlock | CVE | ExploitTechnical DescriptionThird Party Advisory |
| https://mandomat.github.io/2023-03-15-testing-mojobox-security/ | [email protected] | ExploitTechnical DescriptionThird Party Advisory |
| https://packetstormsecurity.com/2307-exploits/mojobox14-replay.txt | [email protected] | Third Party AdvisoryVDB Entry |
| https://www.whid.ninja/blog/mojobox-yet-another-not-so-smartlock | [email protected] | ExploitTechnical DescriptionThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-294 | Authentication Bypass by Capture-replay | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| showmojo mojobox firmware | 1.4 |
CPE
Remediation
| |
| showmojo mojobox | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Jul 28, 2023 | Initial Analysis | [email protected] |