
A security assessment of the Beat XP VEGA Smartwatch (Firmware RB303ATV006229) focused on Bluetooth Low Energy (BLE) connectivity revealed a design and implemen tation weakness that enables a nearby BLE central device to establish and retain the single available BLE session without authentication or session access control.
A security assessment of the Beat XP VEGA Smartwatch (Firmware RB303ATV006229) focused on Bluetooth Low Energy (BLE) connectivity revealed a design and implementation weakness that enables a nearby BLE central device to establish and retain the single available BLE session without authentication or session access control.
The Proof of Concept (PoC) for this vulnerability is documented in the attached PDF, which was originally provided for internal security review to the respective organization.
Discoverer : CipherX1802