Vulnerability CVE-2019-9862


Published: 2019-03-27

Description:
An issue was discovered on ABUS Secvest wireless alarm system FUAA50000 3.01.01 in conjunction with Secvest remote control FUBE50014 or FUBE50015. Because "encrypted signal transmission" is missing, an attacker is able to eavesdrop sensitive data as cleartext (for instance, the current rolling code state).

Type:

CWE-200

(Information Exposure)

CVSS2 => (AV:A/AC:L/Au:N/C:P/I:N/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
3.3/10
2.9/10
6.5/10
Exploit range
Attack complexity
Authentication
Adjacent network
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
None
None
Affected software
ABUS -> Secvest wireless alarm system fuaa50000 firmware 
ABUS -> Secvest wireless remote control fube50014 firmware 
ABUS -> Secvest wireless remote control fube50015 firmware 

 References:
https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2018-035.txt

Copyright 2024, cxsecurity.com

 

Back to Top