PT-2019-19898 · Abus · Abus Secvest Remote Controls+1

Publicado

2019-03-27

·

Atualizado

2021-07-21

·

CVE-2019-9863

CVSS v3.1

10

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ABUS Secvest wireless alarm system FUAA50000 version 3.01.01 ABUS Secvest remote controls FUBE50014 (affected versions not specified) ABUS Secvest remote controls FUBE50015 (affected versions not specified)
Description The issue arises from the use of an insecure algorithm for rolling codes, allowing an attacker to predict valid future rolling codes. This enables unauthorized remote control of the alarm system.
Recommendations For ABUS Secvest wireless alarm system FUAA50000 version 3.01.01, consider disabling remote control functionality until a secure algorithm for rolling codes is implemented. For ABUS Secvest remote controls FUBE50014 and FUBE50015, restrict their use with the alarm system until a fix is provided, to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use of Insufficiently Random Values

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-9863

Produtos afetados

Abus Secvest Remote Controls
Abus Secvest Wireless Alarm System