Beat XP VEGA Smartwatch Denial-of-Service Vulnerability via Bluetooth Low Energy Connection
Vulnerability
A denial-of-service vulnerability has been identified in the Beat XP VEGA Smartwatch, specifically in firmware version RB303ATV006229. The issue arises from a design flaw that allows a nearby device to connect via Bluetooth Low Energy (BLE) and monopolize the single available BLE session. This can be done without any authentication or access controls, effectively causing a denial-of-service condition by preventing the smartwatch from establishing new BLE connections.
Impact
Exploitation of this vulnerability leads to a denial-of-service condition, where the smartwatch is unable to accept new Bluetooth Low Energy connections, potentially disrupting its functionality or connectivity with other devices.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
