PT-2019-19897 · Abus · Abus Secvest

Matthias Deeg

+1

·

Publicado

2019-03-27

·

Atualizado

2020-08-24

·

CVE-2019-9862

CVSS v3.1

6.5

Média

VetorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions ABUS Secvest wireless alarm system FUAA50000 version 3.01.01
Description An issue was discovered where sensitive data, such as the current rolling code state, is transmitted in cleartext due to the lack of "encrypted signal transmission". This allows an attacker to eavesdrop on the data.
Recommendations For ABUS Secvest wireless alarm system FUAA50000 version 3.01.01, consider implementing encrypted signal transmission to prevent eavesdropping of sensitive data. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Correção

Missing Encryption of Sensitive Data

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-9862

Produtos afetados

Abus Secvest