PT-2019-19898 · Abus · Abus Secvest Remote Controls+1
Publicado
2019-03-27
·
Atualizado
2021-07-21
·
CVE-2019-9863
CVSS v3.1
10
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
ABUS Secvest wireless alarm system FUAA50000 version 3.01.01
ABUS Secvest remote controls FUBE50014 (affected versions not specified)
ABUS Secvest remote controls FUBE50015 (affected versions not specified)
Description
The issue arises from the use of an insecure algorithm for rolling codes, allowing an attacker to predict valid future rolling codes. This enables unauthorized remote control of the alarm system.
Recommendations
For ABUS Secvest wireless alarm system FUAA50000 version 3.01.01, consider disabling remote control functionality until a secure algorithm for rolling codes is implemented.
For ABUS Secvest remote controls FUBE50014 and FUBE50015, restrict their use with the alarm system until a fix is provided, to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Use of Insufficiently Random Values
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Abus Secvest Remote Controls
Abus Secvest Wireless Alarm System