CVE-2020-14158

The ABUS Secvest FUMO50110 hybrid module does not have any security mechanism that ensures confidentiality or integrity of RF packets that are exchanged with an alarm panel. This makes it easier to conduct wAppLoxx authentication-bypass attacks.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:abus:secvest_hybrid_fumo50110_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:abus:secvest_hybrid_fumo50110:-:*:*:*:*:*:*:*

History

21 Nov 2024, 05:02

Type Values Removed Values Added
References () http://packetstormsecurity.com/files/158692/ABUS-Secvest-Hybrid-Module-FUMO50110-Authentication-Bypass.html - Third Party Advisory () http://packetstormsecurity.com/files/158692/ABUS-Secvest-Hybrid-Module-FUMO50110-Authentication-Bypass.html - Third Party Advisory
References () http://seclists.org/fulldisclosure/2020/Jul/36 - Mailing List, Third Party Advisory () http://seclists.org/fulldisclosure/2020/Jul/36 - Mailing List, Third Party Advisory
References () https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2020-015.txt - Third Party Advisory () https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2020-015.txt - Third Party Advisory

Information

Published : 2020-07-30 14:15

Updated : 2024-11-21 05:02


NVD link : CVE-2020-14158

Mitre link : CVE-2020-14158

CVE.ORG link : CVE-2020-14158


JSON object : View

Products Affected

abus

  • secvest_hybrid_fumo50110_firmware
  • secvest_hybrid_fumo50110
CWE
CWE-287

Improper Authentication