CVE-2019-9860

Due to unencrypted signal communication and predictability of rolling codes, an attacker can "desynchronize" an ABUS Secvest wireless remote control (FUBE50014 or FUBE50015) relative to its controlled Secvest wireless alarm system FUAA50000 3.01.01, so that sent commands by the remote control are not accepted anymore.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:abus:secvest_wireless_alarm_system_fuaa50000_firmware:3.01.01:*:*:*:*:*:*:*
cpe:2.3:h:abus:secvest_wireless_alarm_system_fuaa50000:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:abus:secvest_wireless_remote_control_fube50014_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:abus:secvest_wireless_remote_control_fube50014:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:abus:secvest_wireless_remote_control_fube50015_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:abus:secvest_wireless_remote_control_fube50015:-:*:*:*:*:*:*:*

History

21 Nov 2024, 04:52

Type Values Removed Values Added
References () https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2018-036.txt - Third Party Advisory () https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2018-036.txt - Third Party Advisory

Information

Published : 2019-03-27 15:29

Updated : 2024-11-21 04:52


NVD link : CVE-2019-9860

Mitre link : CVE-2019-9860

CVE.ORG link : CVE-2019-9860


JSON object : View

Products Affected

abus

  • secvest_wireless_remote_control_fube50015
  • secvest_wireless_remote_control_fube50014_firmware
  • secvest_wireless_alarm_system_fuaa50000
  • secvest_wireless_alarm_system_fuaa50000_firmware
  • secvest_wireless_remote_control_fube50015_firmware
  • secvest_wireless_remote_control_fube50014
CWE
CWE-319

Cleartext Transmission of Sensitive Information

CWE-330

Use of Insufficiently Random Values