CVE-2016-2398

Comcast XFINITY Home Security System does not properly maintain base-station communication, which allows physically proximate attackers to defeat sensor functionality by interfering with ZigBee 2.4 GHz transmissions.
Configurations

Configuration 1 (hide)

cpe:2.3:o:comcast:xfinity_home_security_system:*:*:*:*:*:*:*:*

History

21 Nov 2024, 02:48

Type Values Removed Values Added
References () http://www.kb.cert.org/vuls/id/418072 - Third Party Advisory, US Government Resource () http://www.kb.cert.org/vuls/id/418072 - Third Party Advisory, US Government Resource
References () http://www.wired.com/2016/01/xfinitys-security-system-flaws-open-homes-to-thieves/ - () http://www.wired.com/2016/01/xfinitys-security-system-flaws-open-homes-to-thieves/ -
References () https://community.rapid7.com/community/infosec/blog/2016/01/05/r7-2015-23-comcast-xfinity-home-security-system-insecure-fail-open - () https://community.rapid7.com/community/infosec/blog/2016/01/05/r7-2015-23-comcast-xfinity-home-security-system-insecure-fail-open -

Information

Published : 2016-02-17 16:59

Updated : 2024-11-21 02:48


NVD link : CVE-2016-2398

Mitre link : CVE-2016-2398

CVE.ORG link : CVE-2016-2398


JSON object : View

Products Affected

comcast

  • xfinity_home_security_system
CWE
CWE-254

7PK - Security Features