CVE-2023-7007 describes a critical vulnerability in the Sciener server, where insufficient validation of GatewayG2 connection requests enables an impersonation attack. This flaw allows an attacker to obtain the unlockKey field, potentially compromising smart lock security. With a CVSS score of 8.2 (HIGH), this vulnerability is remotely exploitable with low attack complexity, leading to high confidentiality impact and low integrity impact. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered some community discussion and media coverage, indicating awareness within the cybersecurity landscape.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Sciener | Gateway G2 | >= 6.0.0, <= 6.0.0CNA affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.