PT-2017-14604 · Amazon · Amazon Key+1

Ben Caudill

·

Published

2017-11-16

·

Updated

2019-10-03

·

CVE-2017-16867

CVSS v3.1

6.5

Medium

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Amazon Key through 2017-11-16
Description The issue makes it easier for delivery drivers or attackers to freeze a camera and enter a house. This can occur if a delivery driver fails to ensure a locked door before leaving or if an attacker exploits the mishandling of Cloud Cam 802.11 deauthentication frames during the delivery process.
Recommendations For Amazon Key through 2017-11-16, ensure that delivery drivers always lock the door before leaving the house to minimize the risk of exploitation. Additionally, consider implementing an alternative security measure to monitor and secure the premises until a fix is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2017-16867

Affected Products

Amazon Key
Cloud Cam