PT-2017-14604 · Amazon · Amazon Key+1
Ben Caudill
·
Published
2017-11-16
·
Updated
2019-10-03
·
CVE-2017-16867
CVSS v3.1
6.5
Medium
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Amazon Key through 2017-11-16
Description
The issue makes it easier for delivery drivers or attackers to freeze a camera and enter a house. This can occur if a delivery driver fails to ensure a locked door before leaving or if an attacker exploits the mishandling of Cloud Cam 802.11 deauthentication frames during the delivery process.
Recommendations
For Amazon Key through 2017-11-16, ensure that delivery drivers always lock the door before leaving the house to minimize the risk of exploitation. Additionally, consider implementing an alternative security measure to monitor and secure the premises until a fix is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Amazon Key
Cloud Cam