Vulnerabilities > Oklok Project

DATE CVE VULNERABILITY TITLE RISK
2020-05-04 CVE-2020-8792 Information Exposure vulnerability in Oklok Project Oklok 3.1.1
The OKLOK (3.1.1) mobile companion app for Fingerprint Bluetooth Padlock FB50 (2.3) has an information-exposure issue.
network
low complexity
oklok-project CWE-200
5.0
2020-05-04 CVE-2020-8791 Information Exposure vulnerability in Oklok Project Oklok 3.1.1
The OKLOK (3.1.1) mobile companion app for Fingerprint Bluetooth Padlock FB50 (2.3) allows remote attackers to submit API requests using authenticated but unauthorized tokens, resulting in IDOR issues.
network
low complexity
oklok-project CWE-200
4.0
2020-05-04 CVE-2020-8790 Weak Password Requirements vulnerability in Oklok Project Oklok 3.1.1
The OKLOK (3.1.1) mobile companion app for Fingerprint Bluetooth Padlock FB50 (2.3) has weak password requirements combined with improper restriction of excessive authentication attempts, which could allow a remote attacker to discover user credentials and obtain access via a brute force attack.
network
low complexity
oklok-project CWE-521
7.5
2020-05-04 CVE-2020-10876 Improper Restriction of Excessive Authentication Attempts vulnerability in Oklok Project Oklok 3.1.1
The OKLOK (3.1.1) mobile companion app for Fingerprint Bluetooth Padlock FB50 (2.3) does not correctly implement its timeout on the four-digit verification code that is required for resetting passwords, nor does it properly restrict excessive verification attempts.
network
low complexity
oklok-project CWE-307
5.0