An issue was discovered on ABUS Secvest wireless alarm system FUAA50000 3.01.01 in conjunction with Secvest remote control FUBE50014 or FUBE50015. Because "encrypted signal transmission" is missing, an attacker is able to eavesdrop sensitive data as cleartext (for instance, the current rolling code state).
References
Link | Resource |
---|---|
https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2018-035.txt | Exploit Third Party Advisory |
https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2018-035.txt | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
History
21 Nov 2024, 04:52
Type | Values Removed | Values Added |
---|---|---|
References | () https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2018-035.txt - Exploit, Third Party Advisory |
Information
Published : 2019-03-27 14:29
Updated : 2024-11-21 04:52
NVD link : CVE-2019-9862
Mitre link : CVE-2019-9862
CVE.ORG link : CVE-2019-9862
JSON object : View
Products Affected
abus
- secvest_wireless_remote_control_fube50015
- secvest_wireless_remote_control_fube50014_firmware
- secvest_wireless_alarm_system_fuaa50000
- secvest_wireless_alarm_system_fuaa50000_firmware
- secvest_wireless_remote_control_fube50015_firmware
- secvest_wireless_remote_control_fube50014
CWE
CWE-311
Missing Encryption of Sensitive Data