CVE-2023-7017: Sciener Kontrol Lux

Critical severity, CVSS 9.8. EPSS: 0.3% chance of exploitation in the next 30 days.

Sciener locks' firmware update mechanism do not authenticate or validate firmware updates if passed to the lock through the Bluetooth Low Energy service. A challenge request can be sent to the lock with a command to prepare for an update, rather than an unlock request, allowing an attacker to compromise the device.

Affected products

  • Sciener Kontrol Lux: from 6.5, up to and including 6.5.07
  • Sciener Kontrol Lux Firmware: from 6.5, up to and including 6.5.07

Published 2024-03-15. Last modified 2026-06-17.