Summary
Critical vulnerabilities have been discovered in the utilized Bluetooth component.
For more information see: https://kb.cert.org/vuls/id/799380
Impact
Pepperl+Fuchs analyzed and identified affected devices.
An unauthorized attacker could gain access to the audio communication and listen to the conversation via Bluetooth.
This attack can only be carried out at close range and is limited by the radio range of Bluetooth.
The impact of the vulnerabilities on the affected device may result in
information disclosure
Affected Product(s)
Model no. | Product name | Affected versions |
---|---|---|
RSM-EX01B product Family | Firmware vers:all/* |
Vulnerabilities
Expand / Collapse allRemediation
The device will play a confirmation sound when a Bluetooth connection is successfully established and a status LED labeled BT indicates that a Bluetooth connection is active.
This can be used to detect an unauthenticated connection.
Acknowledgments
Pepperl+Fuchs SE thanks the following parties for their efforts:
- CERTVDE for coordination (see https://certvde.com )
- Pepperl+Fuchs SE for reporting (see https://www.pepperl-fuchs.com )
Revision History
Version | Date | Summary |
---|---|---|
1 | 05/16/2022 16:00 | initial revision |
2 | 05/22/2025 15:03 | Fix: quotation mark |